Microsoft-Windows-TCPIP
624 events across 2 channels
Event ID 1001: TCP: endpoint Endpoint (Family=AddressFamily, PID=Pid) created with status = Status.
#Description
TCP: endpoint Endpoint (Family=AddressFamily, PID=Pid) created with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Endpoint Pointer | |
AddressFamily UInt32 | |
Pid UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1001",
"version": "0",
"level": "4",
"task": "1001",
"opcode": "0",
"keywords": 9223372036854776832,
"time_created": "2026-03-16T00:21:40.064345500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Status": "0x0",
"Endpoint": "0xFFFF980A15F74B50",
"AddressFamily": " 23",
"Pid": " 3688"
},
"message": ""
}
Event ID 1002: TCP: Tcb Tcb (local=LocalAddress remote=RemoteAddress) requested to connect.
#Description
TCP: Tcb Tcb (local=LocalAddress remote=RemoteAddress) requested to connect.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
NewState UInt32 | |
RexmitCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1002",
"version": "0",
"level": "4",
"task": "1002",
"opcode": "0",
"keywords": 9223372054034646144,
"time_created": "2026-03-16T00:21:40.119471500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"NewState": " 0",
"RexmitCount": " 0"
},
"message": ""
}
Event ID 1003: TCP: Inspect Connect has been completed on Tcb Tcb with status = Status.
#Description
TCP: Inspect Connect has been completed on Tcb Tcb with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Status UInt32 | NTSTATUS reference |
AddressFamily UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1003",
"version": "0",
"level": "4",
"task": "1003",
"opcode": "0",
"keywords": 9223372054034646144,
"time_created": "2026-03-16T00:21:40.119557300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Status": "0x0",
"AddressFamily": " 0"
},
"message": ""
}
Event ID 1004: TCP: Tcb Tcb is going to output SYN with ISN = ISN, RcvWnd = RcvWnd, RcvWndScale = RcvWndScale.
#Description
TCP: Tcb Tcb is going to output SYN with ISN = ISN, RcvWnd = RcvWnd, RcvWndScale = RcvWndScale.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
ISN UInt32 | |
RcvWnd UInt32 | |
RcvWndScale UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1004",
"version": "0",
"level": "4",
"task": "1004",
"opcode": "0",
"keywords": 9223372058329612416,
"time_created": "2026-03-16T00:21:40.119603700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"ISN": "155000287",
"RcvWnd": " 64240",
"RcvWndScale": "8"
},
"message": ""
}
Event ID 1005: TCP: endpoint bind failed: address LocalAddressLength cannot be resolved (LocalAddress).
#Description
TCP: endpoint bind failed: address LocalAddressLength cannot be resolved (LocalAddress).
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1006: TCP: endpoint (sockaddr=LocalAddressLength) bind failed: port-acquisition status = LocalAddress.
#Description
TCP: endpoint (sockaddr=LocalAddressLength) bind failed: port-acquisition status = LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1007: TCP: endpoint (sockaddr=LocalAddressLength) bind failed: inspection status = LocalAddress.
#Description
TCP: endpoint (sockaddr=LocalAddressLength) bind failed: inspection status = LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1008: TCP: endpoint (sockaddr=LocalAddressLength) bound.
#Description
TCP: endpoint (sockaddr=LocalAddressLength) bound.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1008",
"version": "1",
"level": "4",
"task": "1008",
"opcode": "0",
"keywords": 9223372036854776841,
"time_created": "2026-03-16T00:21:40.119123100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0da8a910-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A0DA8A910",
"LocalAddressLength": " 16",
"LocalAddress": "0.0.0.0:52999",
"Status": "0x0"
},
"message": ""
}
Event ID 1009: TCP: endpoint (sockaddr=LocalAddressLength) closed.
#Description
TCP: endpoint (sockaddr=LocalAddressLength) closed.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1009",
"version": "1",
"level": "4",
"task": "1009",
"opcode": "0",
"keywords": 9223372105574253569,
"time_created": "2026-03-16T00:21:40.064514900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A15F74B50",
"LocalAddressLength": " 28",
"LocalAddress": "::",
"Status": "0x0"
},
"message": ""
}
Event ID 1010: TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: address family not attached.
#Description
TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1011: TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: compartment CompartmentId not found.
#Description
TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: compartment CompartmentId not found.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1012: TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: inspection status Status.
#Description
TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: inspection status Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1013: TCP: endpoint (Family=CompartmentId PID=Status) created.
#Description
TCP: endpoint (Family=CompartmentId PID=Status) created.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1013",
"version": "2",
"level": "4",
"task": "1013",
"opcode": "0",
"keywords": 9223372036854776833,
"time_created": "2026-03-16T00:21:40.064333400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A15F74B50",
"LocalAddressLength": " 0",
"LocalAddress": "",
"Status": "0x0",
"ProcessId": " 3688",
"CompartmentId": " 1",
"AddressFamily": " 23",
"ProcessStartKey": "2814749767106643"
},
"message": ""
}
Event ID 1014: TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: Route lookup status = Status, TCB = Tcb.
#Description
TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: Route lookup status = Status, TCB = Tcb.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1015: TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: connection insertion.
#Event ID 1016: TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: client rejection status = Status.
#Description
TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: client rejection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1017: TCP: listener (local=LocalAddress remote=RemoteAddress) accept completed.
#Description
TCP: listener (local=LocalAddress remote=RemoteAddress) accept completed. TCB = Tcb. PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1017",
"version": "1",
"level": "4",
"task": "1017",
"opcode": "0",
"keywords": 9223372054034646150,
"time_created": "2026-03-16T00:21:38.720229400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0x0",
"ProcessId": " 4",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "2814749767106561"
},
"message": ""
}
Event ID 1018: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: address family not attached.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1019: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: compartment Compartment not found.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: compartment Compartment not found.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1020: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: inspection status = Status.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: inspection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1021: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: route lookup status = Status.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: route lookup status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1022: TCP: Bypass rate limiting since flag is set on path Path (local=LocalAddress remote=RemoteAddress).
#Event ID 1023: TCP: Charge rate limiting quota and set rate limiting flag for path Path (local=LocalAddress remote=RemoteAddress).
#Event ID 1024: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) deferred.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) deferred.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1025: TCP: ConnectionRateLimitDepth rate-limiting paths ConnectionRateLimitBacklog backlogged connections.
#Description
TCP: ConnectionRateLimitDepth rate-limiting paths ConnectionRateLimitBacklog backlogged connections.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | |
ReassemblyLimitViolations UInt32 | |
ConnectionRateLimitBacklog UInt32 | |
ConnectionRateLimitViolations UInt32 | |
LandAttackSegmentsDropped UInt32 | |
ConnectionRateLimitDepth UInt32 |
Event ID 1026: TCP: Release and set rate limiting flag on path Path (local=LocalAddress remote=RemoteAddress).
#Event ID 1027: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1028: TCP: Clear rate limiting flag on path Path (local=LocalAddress remote=RemoteAddress) since connection is cancelled.
#Event ID 1029: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connection cancelled.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connection cancelled.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1030: TCP: connection (local=LocalAddressLength remote=RemoteAddressLength) connect failed: connection insertion status = RemoteAddress.
#Description
TCP: connection (local=LocalAddressLength remote=RemoteAddressLength) connect failed: connection insertion status = RemoteAddress.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
NewState UInt32 | |
RexmitCount UInt32 |
Event ID 1031: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect proceeding.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect proceeding.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1031",
"version": "1",
"level": "4",
"task": "1031",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-16T00:21:40.119618200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A15CE6AE0",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1032: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released due to cancel.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released due to cancel.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1033: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect completed.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect completed. PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1033",
"version": "1",
"level": "4",
"task": "1033",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-16T00:21:40.246461800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"Status": "0x0",
"ProcessId": " 3688",
"Compartment": " 0",
"Tcb": "0xFFFF980A15CE6AE0",
"ProcessStartKey": "2814749767106643"
},
"message": ""
}
Event ID 1034: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect attempt failed with status = Status.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect attempt failed with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1034",
"version": "1",
"level": "2",
"task": "1034",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-15T23:27:04.870761200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{009c52a0-d780-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3912",
"thread_id": "13412"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::1]:51202",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::1]:389",
"Status": "0xC0000120",
"ProcessId": " 3912",
"Compartment": " 0",
"Tcb": "0xFFFFD780009C52A0",
"ProcessStartKey": "3940649673949252"
},
"message": ""
}
Event ID 1035: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-complete inspect status = Status.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-complete inspect status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1036: TCP: ApplySynOptions, failed to create session state with status = Status, TCB = Tcb.
#Description
TCP: ApplySynOptions, failed to create session state with status = Status, TCB = Tcb.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1037: TCP: ApplySynOptions, failed to update DF with status = Status, TCB = Tcb.
#Description
TCP: ApplySynOptions, failed to update DF with status = Status, TCB = Tcb.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1038: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) close issued.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) close issued.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1038",
"version": "1",
"level": "4",
"task": "1038",
"opcode": "0",
"keywords": 9223372105574253572,
"time_created": "2026-03-16T00:21:38.733239500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1039: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort issued.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort issued.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1039",
"version": "1",
"level": "4",
"task": "1039",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:22:37.889609500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52990",
"RemoteAddressLength": " 16",
"RemoteAddress": "52.159.108.190:443",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0E584560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1040: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort completed.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort completed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1040",
"version": "1",
"level": "4",
"task": "1040",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:22:37.890003800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52990",
"RemoteAddressLength": " 16",
"RemoteAddress": "52.159.108.190:443",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0E584560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1041: TCP: Injecting disconnect on a shutdown TCB failed.
#Event ID 1042: TCP: connection disconnect Injected, length=Length.
#Description
TCP: connection disconnect Injected, length=Length.
Message #
Fields #
| Name | Description |
|---|---|
Length Pointer | |
Timeout UInt64 | |
Injected UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1042",
"version": "0",
"level": "4",
"task": "1042",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:21:38.732224500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Length": "0x0",
"Timeout": "0x0",
"Injected": "issued"
},
"message": ""
}
Event ID 1043: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) disconnect completed.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) disconnect completed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 | |
Inspect Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1043",
"version": "1",
"level": "4",
"task": "1043",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:21:38.732982900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1044: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) shutdown initiated (Status).
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) shutdown initiated (Status). PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1044",
"version": "1",
"level": "4",
"task": "1044",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:21:38.733255900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0xC0000241",
"ProcessId": " 4",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "2814749767106561"
},
"message": ""
}
Event ID 1045: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-request timeout expired.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-request timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1046: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: retransmission timeout expired.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: retransmission timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1046",
"version": "1",
"level": "4",
"task": "1046",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-15T23:32:02.749394100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.11:51269",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.21:389",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFFD78FF9CA95F0",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1047: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: keep-alive timeout expired.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: keep-alive timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1048: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: disconnect timeout expired.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: disconnect timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1049: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: extended statistics status = Status.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: extended statistics status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1050: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: port-acquisition status = Status.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: port-acquisition status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1051: TCP: connection Tcb transition from OldState to NewState, SndNxt = SndNxt.
#Description
TCP: connection Tcb transition from OldState to NewState, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
OldState UInt32 | |
NewState UInt32 | |
SndNxt UInt32 | |
Tcb Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1051",
"version": "0",
"level": "4",
"task": "1051",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:38.719167800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0ef4b580-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"OldState": " 1",
"NewState": " 3",
"SndNxt": " 0",
"Tcb": "0xFFFF980A0EEE7560"
},
"message": ""
}
Event ID 1052: TCP: Process with PID = ProcessId reserved NumberOfPorts ports starting at StartPort.
#Description
TCP: Process with PID = ProcessId reserved NumberOfPorts ports starting at StartPort.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | |
Status UInt32 | NTSTATUS reference |
StartPort UInt16 | |
NumberOfPorts UInt16 | |
ProcessStartKey UInt64 |
Event ID 1053: TCP: Process with PID = ProcessId failed to reserve NumberOfPorts ports starting at StartPort with status = Status.
#Description
TCP: Process with PID = ProcessId failed to reserve NumberOfPorts ports starting at StartPort with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | |
Status UInt32 | NTSTATUS reference |
StartPort UInt16 | |
NumberOfPorts UInt16 | |
ProcessStartKey UInt64 |
Event ID 1054: TCP: Process with PID = ProcessId completed global port reservation of NumberOfPorts ports starting at StartPort with status = Status.
#Description
TCP: Process with PID = ProcessId completed global port reservation of NumberOfPorts ports starting at StartPort with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | |
Status UInt32 | NTSTATUS reference |
StartPort UInt16 | |
NumberOfPorts UInt16 | |
ProcessStartKey UInt64 |
Event ID 1055: TCP: entering SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
#Description
TCP: entering SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | |
ReassemblyLimitViolations UInt32 | |
ConnectionRateLimitBacklog UInt32 | |
ConnectionRateLimitViolations UInt32 | |
LandAttackSegmentsDropped UInt32 | |
ConnectionRateLimitDepth UInt32 |
Event ID 1056: TCP: reasembly rate-limiting violated ReassemblyLimitViolations times since boot.
#Description
TCP: reasembly rate-limiting violated ReassemblyLimitViolations times since boot.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | |
ReassemblyLimitViolations UInt32 | |
ConnectionRateLimitBacklog UInt32 | |
ConnectionRateLimitViolations UInt32 | |
LandAttackSegmentsDropped UInt32 | |
ConnectionRateLimitDepth UInt32 |
Event ID 1057: TCP: connection rate-limiting violated ConnectionRateLimitViolations times since boot.
#Description
TCP: connection rate-limiting violated ConnectionRateLimitViolations times since boot.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | |
ReassemblyLimitViolations UInt32 | |
ConnectionRateLimitBacklog UInt32 | |
ConnectionRateLimitViolations UInt32 | |
LandAttackSegmentsDropped UInt32 | |
ConnectionRateLimitDepth UInt32 |
Event ID 1058: TCP: land attack has dropped LandAttackSegmentsDropped packets since boot.
#Description
TCP: land attack has dropped LandAttackSegmentsDropped packets since boot.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | |
ReassemblyLimitViolations UInt32 | |
ConnectionRateLimitBacklog UInt32 | |
ConnectionRateLimitViolations UInt32 | |
LandAttackSegmentsDropped UInt32 | |
ConnectionRateLimitDepth UInt32 |
Event ID 1059: TCP: low memory state detected.
#Event ID 1060: TCP: leaving low memory state.
#Event ID 1061: TCP: address family AddressFamily added to interface InterfaceIndex.
#Event ID 1062: TCP: address family AddressFamily removed from interface InterfaceIndex.
#Event ID 1063: TCP: leaving SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
#Description
TCP: leaving SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | |
ReassemblyLimitViolations UInt32 | |
ConnectionRateLimitBacklog UInt32 | |
ConnectionRateLimitViolations UInt32 | |
LandAttackSegmentsDropped UInt32 | |
ConnectionRateLimitDepth UInt32 |
Event ID 1064: TCP: Connection Tcb TimerType timer started.
#Description
TCP: Connection Tcb TimerType timer started. Scheduled to expire in WaitTimeMilliseconds ms.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
TimerType UInt32 | |
WaitTimeMilliseconds UInt32 | |
Processor UInt32 | |
LastInterruptTime UInt64 | |
LastMicroseconds UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1064",
"version": "1",
"level": "5",
"task": "1064",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:34.388854500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TimerType": " 0",
"WaitTimeMilliseconds": " 201",
"Processor": " 9",
"LastInterruptTime": "577532689097",
"LastMicroseconds": "57753289800",
"CachedKQPCValues": "577532898003",
"CachedFrequencyValues": "10000000"
},
"message": ""
}
Event ID 1065: TCP: Connection Tcb stopping TimerType timer.
#Description
TCP: Connection Tcb stopping TimerType timer.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
TimerType UInt32 | |
WaitTimeMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1065",
"version": "0",
"level": "5",
"task": "1065",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:34.388747900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TimerType": " 7",
"WaitTimeMilliseconds": " 0"
},
"message": ""
}
Event ID 1066: TCP: Connection Tcb TimerType timer has expired.
#Description
TCP: Connection Tcb TimerType timer has expired.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
TimerType UInt32 | |
WaitTimeMilliseconds UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1066",
"version": "0",
"level": "5",
"task": "1066",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:34.715526000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TimerType": " 2",
"WaitTimeMilliseconds": " 0"
},
"message": ""
}
Event ID 1067: TCP: ISB changed to IsbSize.
#Event ID 1068: TCP: moving RSS indirection table index TableEntry from processor SourceProcessor to processor DestinationProcessor.
#Description
TCP: moving RSS indirection table index TableEntry from processor SourceProcessor to processor DestinationProcessor.
Message #
Fields #
| Name | Description |
|---|---|
SourceProcessor UInt32 | |
SourceActivity UInt32 | |
DestinationProcessor UInt32 | |
DestinationActivity UInt32 | |
PartitionMovesRemaining UInt32 | |
TableEntry UInt8 |
Event ID 1069: TCP: connection Tcb: Timeout Event updated cwnd = Cwnd and updated ssthresh = SSThresh.
#Event ID 1070: TCP: connection Tcb: Rtt sample recorded RttSample.
#Event ID 1071: TCP: connection Tcb: Cumulative ACK updated cwnd = Cwnd.
#Event ID 1072: TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh.
#Event ID 1073: TCP: connection Tcb: Sent data with number of bytes = NumBytes and Sequence number = SeqNo.
#Description
TCP: connection Tcb: Sent data with number of bytes = NumBytes and Sequence number = SeqNo.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
RttSample UInt32 | |
NumBytes UInt32 | |
SeqNo UInt32 | |
SndUna UInt32 | |
Round UInt32 | |
SRTT UInt32 | |
RTO UInt32 | |
DWnd UInt32 | |
BaseRtt UInt32 | |
DupAckCount UInt32 |
Event ID 1074: TCP: connection Tcb: Received data with number of bytes = NumBytes.
#Description
TCP: connection Tcb: Received data with number of bytes = NumBytes. ThSeq = SeqNo.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NumBytes UInt32 | |
SeqNo UInt32 | |
NumPkt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1074",
"version": "0",
"level": "4",
"task": "1074",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.390777500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"NumBytes": " 6",
"SeqNo": "3537939053"
},
"message": ""
}
Event ID 1075: TCP: connection Tcb: ECN Echo updated cwnd = Cwnd and updated ssthresh = SSThresh.
#Event ID 1076: TCP: connection Tcb: Spurious timeout with SndUna = SndUna.
#Event ID 1077: TCP: connection Tcb: Send Retransmit round with SndUna = SeqNo, Round = Round, SRTT = SRTT, RTO = RTO.
#Description
TCP: connection Tcb: Send Retransmit round with SndUna = SeqNo, Round = Round, SRTT = SRTT, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
RttSample UInt32 | |
NumBytes UInt32 | |
SeqNo UInt32 | |
SndUna UInt32 | |
Round UInt32 | |
SRTT UInt32 | |
RTO UInt32 | |
DWnd UInt32 | |
BaseRtt UInt32 | |
DupAckCount UInt32 |
Event ID 1078: TCP: connection Tcb: Entered loss recovery phase with SndUna = SndUna and SndMax = SndMax.
#Description
TCP: connection Tcb: Entered loss recovery phase with SndUna = SndUna and SndMax = SndMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1078",
"version": "0",
"level": "4",
"task": "1078",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-16T00:21:40.489867400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155002622",
"SndMax": "155007102"
},
"message": ""
}
Event ID 1079: TCP: connection Tcb: Leaving loss recovery phase with SndUna = SndUna and SndMax = SndMax.
#Description
TCP: connection Tcb: Leaving loss recovery phase with SndUna = SndUna and SndMax = SndMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1079",
"version": "0",
"level": "4",
"task": "1079",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-16T00:21:40.494494300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6656"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155007102",
"SndMax": "155007102"
},
"message": ""
}
Event ID 1080: TCP: connection Tcb entering SACK mode with SndUna = SndUna.
#Event ID 1081: TCP: connection Tcb leaving SACK mode with SndUna = SndUna.
#Event ID 1082: TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
#Description
TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
RttSample UInt32 | |
NumBytes UInt32 | |
SeqNo UInt32 | |
SndUna UInt32 | |
Round UInt32 | |
SRTT UInt32 | |
RTO UInt32 | |
DWnd UInt32 | |
BaseRtt UInt32 | |
DupAckCount UInt32 |
Event ID 1084: TCP: connection Tcb entered BH, BH MSS BHMSS, original MSS OriginalMSS.
#Event ID 1085: TCP: connection Tcb Exiting BH due to TraceString, BH mss BHMSS, Original MSS OriginalMSS.
#Event ID 1086: TCP: connection Tcb not entering BH due to TraceString.
#Event ID 1087: TCP: connection Tcb spurious RTO detection initiated at SndUna.
#Event ID 1088: TCP: connection Tcb spurious RTO detection terminated at SndUna.
#Event ID 1089: TCP: active connect failed (family=Status) connect-complete inspection failed: status = AddressFamily.
#Description
TCP: active connect failed (family=Status) connect-complete inspection failed: status = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Status UInt32 | NTSTATUS reference |
AddressFamily UInt32 |
Event ID 1090: TCP: TcpReleaseIndicationList: Nbl = NBL.
#Description
TCP: TcpReleaseIndicationList: Nbl = NBL.
Message #
Fields #
| Name | Description |
|---|---|
NBL Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1090",
"version": "0",
"level": "5",
"task": "1090",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.509548500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"NBL": "0xFFFF980A0EE312B0"
},
"message": ""
}
Event ID 1091: TCP: connection Tcb posted an average of NumBytes bytes per send.
#Event ID 1092: TCP: connection (local=LocalAddress remote=RemoteAddress) starting receive window auto-tuning.
#Description
TCP: connection (local=LocalAddress remote=RemoteAddress) starting receive window auto-tuning.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
BufferSize UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1092",
"version": "0",
"level": "5",
"task": "1092",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.316699400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"BufferSize": " 0"
},
"message": ""
}
Event ID 1093: TCP: connection (local=LocalAddress remote=RemoteAddress) ending receive window auto-tuning.
#Description
TCP: connection (local=LocalAddress remote=RemoteAddress) ending receive window auto-tuning.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
BufferSize UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1093",
"version": "0",
"level": "5",
"task": "1093",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:22:31.341328500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e7ae010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51208",
"BufferSize": " 0"
},
"message": ""
}
Event ID 1094: TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because fine-grained RTT estimation could not be started.
#Event ID 1095: TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because receiver bandwidth estimation could not be started.
#Event ID 1096: TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because of receive window tuning allocation failure.
#Event ID 1097: TCP: connection (local=LocalAddress remote=RemoteAddress) auto-tuner adjusted receive buffer size to BufferSize bytes.
#Event ID 1098: TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.
#Description
TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
RttSample UInt32 | |
NumBytes UInt32 | |
SeqNo UInt32 | |
SndUna UInt32 | |
Round UInt32 | |
SRTT UInt32 | |
RTO UInt32 | |
DWnd UInt32 | |
BaseRtt UInt32 | |
DupAckCount UInt32 |
Event ID 1099: TCP: connection Tcb: Connection State = TcbState, Offload State = OcbState.
#Description
TCP: connection Tcb: Connection State = TcbState, Offload State = OcbState. SndNxt = SndNxt, RcvNxt = RcvNxt. NdisStatus = Status.
Message #
Fields #
| Name | Description |
|---|---|
TcbState UInt32 | |
OcbState UInt32 | |
SndNxt UInt32 | |
RcvNxt UInt32 | |
Tcb Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 1100: TCP: SWS avoidance began on connection Tcb.
#Description
TCP: SWS avoidance began on connection Tcb. Timer set for TimerValue ms. BytesToSend = BytesToSend, SendAvailable = SendAvailable, Cwnd = Cwnd, MaxSndWnd = MaxSndWnd.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
TimerValue UInt32 | |
BytesToSend Pointer | |
SendAvailable UInt32 | |
Cwnd UInt32 | |
MaxSndWnd Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1100",
"version": "0",
"level": "4",
"task": "1100",
"opcode": "0",
"keywords": 9223372041149743232,
"time_created": "2026-03-16T00:23:27.100938500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "10580"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"TimerValue": " 5000",
"BytesToSend": "0x10E0",
"SendAvailable": " 18500",
"Cwnd": " 14786",
"MaxSndWnd": "0x400000"
},
"message": ""
}
Event ID 1101: TCP: SWS avoidance ended on connection Tcb.
#Event ID 1102: TCP: connection Tcb send: Beginning zero-window probing with SndUna = SndUna.
#Event ID 1103: TCP: connection Tcb send: Leaving zero-window probing with SndUna = SndUna.
#Event ID 1104: TCP: Option OptionType is going to be set for connection Tcb.
#Description
TCP: Option OptionType is going to be set for connection Tcb.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
OptionType UInt32 | |
SoOptionType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1104",
"version": "0",
"level": "4",
"task": "1104",
"opcode": "0",
"keywords": 9223372311732683780,
"time_created": "2026-03-16T00:23:28.314606700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "1356",
"thread_id": "4456"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"OptionType": " 1",
"SoOptionType": " 0"
},
"message": ""
}
Event ID 1105: TCP: Socket Option SoOptionType is going to be set for connection Tcb.
#Description
TCP: Socket Option SoOptionType is going to be set for connection Tcb.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
OptionType UInt32 | |
SoOptionType UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1105",
"version": "0",
"level": "4",
"task": "1105",
"opcode": "0",
"keywords": 9223372311732683780,
"time_created": "2026-03-16T00:23:28.314680700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "1356",
"thread_id": "4456"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"OptionType": " 0",
"SoOptionType": " 8"
},
"message": ""
}
Event ID 1106: IP: Disconnecting interface InterfaceIndex, trace = TraceString.
#Event ID 1107: TCPIP: Module ModuleNameString started.
#Event ID 1108: TCPIP: Module ModuleNameString stopped.
#Event ID 1109: TCPIP: Failure allocating AllocationObjectString.
#Event ID 1110: TCP: Global parameters updated for Address Family AddressFamily: EnablePMtuDiscovery = EnablePMTUDiscovery, UseRfc1122UrgentPointer = TcpUseRFC1122UrgentPointer, DisableTaskOffload = DisableTaskOff...
#Description
TCP: Global parameters updated for Address Family AddressFamily: EnablePMtuDiscovery = EnablePMTUDiscovery, UseRfc1122UrgentPointer = TcpUseRFC1122UrgentPointer, DisableTaskOffload = DisableTaskOffload, DisableTcpChimneyOffload = EnablePMTUBHDetect, DisableRss = DisableTcpChimneyOffload, EnablePMtuBHDetect = DisableRss, EcnCapability = EcnCapability, MaxDataRetransmissions = TcpMaxDataRetransmissions, KeepAliveTime = KeepAliveTime, KeepAliveInterval = KeepAliveInterval, TimedWaitDelay = TcpTimedWaitDelay, SillyWindowTimeout = SillyWindowTimeout, FinWait2Timeout = TcpFinWait2Delay, CongestionAlgorithm = CongestionAlgorithm, UseRfc1323Timestamps = Tcp1323Opts, AutoTuningLevelLocal = AutoTuningLevelLocal, AutoTuningLevelGroupPolicy = AutoTuningLevelGroupPolicy.
Message #
Fields #
| Name | Description |
|---|---|
AddressFamily UInt32 | |
EnablePMTUDiscovery UInt8 | |
TcpUseRFC1122UrgentPointer UInt8 | |
DisableTaskOffload UInt8 | |
EnablePMTUBHDetect UInt8 | |
DisableTcpChimneyOffload UInt8 | |
DisableRss UInt8 | |
EcnCapability UInt8 | |
TcpMaxDataRetransmissions UInt8 | |
KeepAliveTime UInt32 | |
KeepAliveInterval UInt32 | |
TcpTimedWaitDelay UInt32 | |
SillyWindowTimeout UInt32 | |
TcpFinWait2Delay UInt32 | |
CongestionAlgorithm UInt8 | |
Tcp1323Opts UInt8 | |
AutoTuningLevelLocal UInt32 | |
AutoTuningLevelGroupPolicy UInt32 |
Event ID 1111: TCP: Connection Tcb Large Send Offload, Bytes in segment = BytesInSegment and Bytes remaining = BytesRemaining.
#Description
TCP: Connection Tcb Large Send Offload, Bytes in segment = BytesInSegment and Bytes remaining = BytesRemaining.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
BytesInSegment UInt32 | |
BytesRemaining UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1111",
"version": "0",
"level": "5",
"task": "1111",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.415610100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6972"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"BytesInSegment": " 1492",
"BytesRemaining": " 0"
},
"message": ""
}
Event ID 1112: TCP: Connection Tcb status changed to Status.
#Description
TCP: Connection Tcb status changed to Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Status UInt32 | NTSTATUS reference |
Interface UInt32 | |
PMax UInt32 |
Event ID 1113: TCP: Connection Tcb status = Status, Interface = Interface, PMax = PMax.
#Description
TCP: Connection Tcb status = Status, Interface = Interface, PMax = PMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Status UInt32 | NTSTATUS reference |
Interface UInt32 | |
PMax UInt32 |
Event ID 1114: IP: DAD successful for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
#Description
IP: DAD successful for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
DadState UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 | |
CompartmentId UInt32 |
Event ID 1115: IP: DAD failed for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, DL address of packet = DLAddress.
#Description
IP: DAD failed for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, DL address of packet = DLAddress.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
DadState UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 | |
CompartmentId UInt32 |
Event ID 1116: IP: DAD started for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
#Description
IP: DAD started for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
DadState UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 | |
CompartmentId UInt32 |
Event ID 1117: TCP: listener (sockaddr=SocketAddress PID=ProcessId) activation failed: address family not attached.
#Description
TCP: listener (sockaddr=SocketAddress PID=ProcessId) activation failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1118: TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: compartment CompartmentId not found.
#Description
TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: compartment CompartmentId not found. Status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1119: TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: inspection status=Status.
#Description
TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: inspection status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1120: TCP: listener Listener (sockaddr=SocketAddress) activation failed: inspection status=Status.
#Description
TCP: listener Listener (sockaddr=SocketAddress) activation failed: inspection status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1121: TCP: listener Listener (sockaddr=SocketAddress) bind failed: port-acquisition status=Status.
#Description
TCP: listener Listener (sockaddr=SocketAddress) bind failed: port-acquisition status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1122: TCP: listener Listener (family=AddressFamily PID=ProcessId) bind failed: address SocketAddress cannot be resolved (Status=Status).
#Description
TCP: listener Listener (family=AddressFamily PID=ProcessId) bind failed: address SocketAddress cannot be resolved (Status=Status).
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1123: TCP: listener Listener (sockaddr=SocketAddress) activated.
#Description
TCP: listener Listener (sockaddr=SocketAddress) activated.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1124: TCP: listener Listener (sockaddr=SocketAddress) unbound.
#Description
TCP: listener Listener (sockaddr=SocketAddress) unbound.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | |
AddressLength UInt32 | |
SocketAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1127: IP: IP address = IPv4Address IPProtocol IPv6Address added on interface = Interface, Protocol = Protocol.
#Description
IP: IP address = IPv4Address IPProtocol IPv6Address added on interface = Interface, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
DadState UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 | |
CompartmentId UInt32 | |
PrefixOrigin UInt32 | |
SuffixOrigin UInt32 |
Event ID 1128: IP: IP address = IPv4Address IPProtocol IPv6Address deleted on interface = Interface, Protocol = Protocol.
#Description
IP: IP address = IPv4Address IPProtocol IPv6Address deleted on interface = Interface, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
DadState UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 | |
CompartmentId UInt32 |
Event ID 1130: Framing: Interface operation status change.
#Description
Framing: Interface Interface Operational Status = OperationalStatus, Operational Status Flags = Status.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
OperationalStatus UInt32 | |
Status UInt64 | NTSTATUS reference |
CompartmentId UInt32 |
Event ID 1136: Framing: NDIS pause event on interface InterfaceIndex.
#Event ID 1137: Framing: NDIS restart event on interface InterfaceIndex.
#Event ID 1138: IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Preferred.
#Description
IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Preferred. Interface = Interface.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
DadState UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 |
Event ID 1139: IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Non-preferred.
#Description
IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Non-preferred. Interface = Interface. DadState = DadState.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
DadState UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 |
Event ID 1144: IP: Interface Interface property change.
#Description
IP: Interface Interface property change. Advertise= Advertise, AdvertiseDefaultRoute = AdvertiseDefaultRoute, Forward = Forward, ForwardMulticast = ForwardMulticast, UseNud = UseNud, AdvertisingEnabled = AdvertisingEnabled.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Advertise UInt32 | |
AdvertiseDefaultRoute UInt32 | |
Forward UInt32 | |
ForwardMulticast UInt32 | |
UseNud UInt32 | |
AdvertisingEnabled UInt32 | |
WeakHostSend UInt32 | |
WeakHostReceive UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
StrictSourceForwarding UInt32 |
Event ID 1145: IP: Route Route created on interface Interface.
#Description
IP: Route Route created on interface Interface. Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 DestinationPrefixLength, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime.
Message #
Fields #
| Name | Description |
|---|---|
Route Pointer | |
Interface UInt32 | |
CompartmentId UInt32 | |
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
DestinationPrefixLength UInt32 | |
ValidLifetime UInt64 | |
PreferredLifetime UInt64 | |
Metric UInt32 | |
Loopback UInt32 | |
AutoconfigureAddress UInt32 | |
Publish UInt32 | |
Immortal UInt32 | |
IPUnicastroutedeletionreason UInt32 |
Event ID 1146: IP: Route Route deleted on interface Interface, Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 Destinatio...
#Description
IP: Route Route deleted on interface Interface, Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 DestinationPrefixLength, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Reason = %19.
Message #
Fields #
| Name | Description |
|---|---|
Route Pointer | |
Interface UInt32 | |
CompartmentId UInt32 | |
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
DestinationPrefixLength UInt32 | |
ValidLifetime UInt64 | |
PreferredLifetime UInt64 | |
Metric UInt32 | |
Loopback UInt32 | |
AutoconfigureAddress UInt32 | |
Publish UInt32 | |
Immortal UInt32 | |
IPUnicastroutedeletionreason UInt32 |
Event ID 1147: IP: Route Route property change.
#Description
IP: Route Route property change. Interface = Interface, Compartment = CompartmentId, DestinationPrefix = DestinationPrefix/DestinationPrefixLength, Nexthop = NextHopAddress. Properties: ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Metric = Metric, Loopback = Loopback, AutoconfigureAddress = AutoconfigureAddress, Publish = Publish, Immortal = Immortal.
Message #
Fields #
| Name | Description |
|---|---|
Route Pointer | |
Interface UInt32 | |
CompartmentId UInt32 | |
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
DestinationPrefixLength UInt32 | |
ValidLifetime UInt64 | |
PreferredLifetime UInt64 | |
Metric UInt32 | |
Loopback UInt32 | |
AutoconfigureAddress UInt32 | |
Publish UInt32 | |
Immortal UInt32 | |
IPUnicastroutedeletionreason UInt32 |
Event ID 1148: IP: Neighbor unreachable.
#Event ID 1149: IP: Neighbor reachable.
#Event ID 1150: TCP: CTCP DataTransferTimeout event.
#Event ID 1151: TCP: CTCP Cumulative Ack event Connection Tcb, sequence = SeqNo, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt.
#Description
TCP: CTCP Cumulative Ack event Connection Tcb, sequence = SeqNo, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
RttSample UInt32 | |
NumBytes UInt32 | |
SeqNo UInt32 | |
SndUna UInt32 | |
Round UInt32 | |
SRTT UInt32 | |
RTO UInt32 | |
DWnd UInt32 | |
BaseRtt UInt32 | |
DupAckCount UInt32 |
Event ID 1152: TCP: CTCP Duplicate Ack event.
#Description
TCP: CTCP Duplicate Ack event. Connection Tcb, sequence = SeqNo, SndUna = SndUna, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt, DupAckCount = DupAckCount.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
RttSample UInt32 | |
NumBytes UInt32 | |
SeqNo UInt32 | |
SndUna UInt32 | |
Round UInt32 | |
SRTT UInt32 | |
RTO UInt32 | |
DWnd UInt32 | |
BaseRtt UInt32 | |
DupAckCount UInt32 |
Event ID 1153: TCP: CTCP Send event.
#Event ID 1154: TCP: CTCP ECN event.
#Event ID 1155: TCP: CTCP Spurious timeout event.
#Event ID 1156: TCP: connection Tcb, delivery Delivery, Request Request posted for NumBytes bytes, flags = RequestFlags.
#Description
TCP: connection Tcb, delivery Delivery, Request Request posted for NumBytes bytes, flags = RequestFlags. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1156",
"version": "0",
"level": "4",
"task": "1156",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.389030100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0xFFFF980A15EC82E0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "3537939053"
},
"message": ""
}
Event ID 1157: TCP: connection Tcb delivery Delivery indicated NumBytes bytes accepted Length bytes, status = RequestStatus.
#Description
TCP: connection Tcb delivery Delivery indicated NumBytes bytes accepted Length bytes, status = RequestStatus. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1157",
"version": "0",
"level": "4",
"task": "1157",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.418359700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "8632"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0x0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0xC000021B",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "3537939065"
},
"message": ""
}
Event ID 1158: TCP: connection Tcb delivery Delivery satisfied NumBytes bytes Length requested.
#Description
TCP: connection Tcb delivery Delivery satisfied NumBytes bytes Length requested. IsFullySatisfied = FullySatisfiedORDelayedPush. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1158",
"version": "0",
"level": "4",
"task": "1158",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.390668300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0xFFFF980A15EC82E0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x6",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 1",
"RcvNxt": "3537939053"
},
"message": ""
}
Event ID 1159: TCP: connection Tcb send Injected NumBytes bytes at SndNxt.
#Description
TCP: connection Tcb send Injected NumBytes bytes at SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Injected UnicodeString | |
NumBytes UInt32 | |
SndNxt UInt32 | |
SendAvailable UInt32 | |
ActivityID Pointer | |
SndLimBytesSnd UInt64 | |
SndLimBytesRwin UInt64 | |
SndLimBytesCwnd UInt64 | |
CWnd UInt32 | |
SRtt UInt32 | |
LossRecoveryEpisodes UInt32 | |
RtoEpisodes UInt32 | |
PtoEpisodes UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1159",
"version": "0",
"level": "4",
"task": "1159",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388647300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "posted",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1160: TCP: connection Tcb send transmitted NumBytes bytes at SndNxt.
#Description
TCP: connection Tcb send transmitted NumBytes bytes at SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Injected UnicodeString | |
NumBytes UInt32 | |
SndNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1160",
"version": "0",
"level": "5",
"task": "1160",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388761700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1161: TCP: connection Tcb send advance NumBytes bytes at SndNxt.
#Description
TCP: connection Tcb send advance NumBytes bytes at SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Injected UnicodeString | |
NumBytes UInt32 | |
SndNxt UInt32 | |
SendAvailable UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1161",
"version": "0",
"level": "5",
"task": "1161",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390443300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1162: TCP: CTcp: Connection Tcb Delay window has not kicked in.
#Description
TCP: CTcp: Connection Tcb Delay window has not kicked in.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Status UInt32 | NTSTATUS reference |
AddressFamily UInt32 |
Event ID 1163: TCP: CTcp: Allocated blocks: AssignedBlocks; Assigned blocks: AllocatedBlocks.
#Event ID 1164: TCP: CTcp: Connection Tcb, DWnd = DWnd (Prev = PrevDWnd), BaseRtt = BaseRtt, AverageRtt = AvgRtt, CWnd =Cwnd, DiffWnd = DiffWnd, DWnd increment = DwndIncrement.
#Description
TCP: CTcp: Connection Tcb, DWnd = DWnd (Prev = PrevDWnd), BaseRtt = BaseRtt, AverageRtt = AvgRtt, CWnd =Cwnd, DiffWnd = DiffWnd, DWnd increment = DwndIncrement.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
DWnd UInt32 | |
PrevDWnd UInt32 | |
BaseRtt UInt32 | |
AvgRtt UInt32 | |
Cwnd UInt32 | |
DiffWnd UInt32 | |
DwndIncrement UInt32 |
Event ID 1165: TCP: CTcp: Gamma Autotuning: Connection Tcb Updated Gamma Gamma, Average backlog AverageBacklog, Average backlog across LFPs AverageBacklogAcrossLFP.
#Event ID 1166: TCP: connection Tcb SRTT measurement started (seq = SeqNum, tick = Tick).
#Event ID 1167: TCP: connection Tcb SRTT measurement complete (tick = Tick, sample = RttSample ms, new srtt = NewSrtt ms).
#Description
TCP: connection Tcb SRTT measurement complete (tick = Tick, sample = RttSample ms, new srtt = NewSrtt ms).
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SeqNum UInt32 | |
Tick UInt32 | |
RttSample UInt32 | |
NewSrtt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1167",
"version": "0",
"level": "4",
"task": "1167",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.268231300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7af7e0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4200",
"thread_id": "7084"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"SeqNum": " 0",
"Tick": "66907815",
"RttSample": " 0",
"NewSrtt": " 0"
},
"message": ""
}
Event ID 1168: TCP: connection Tcb: SRTT measurement cancelled.
#Description
TCP: connection Tcb: SRTT measurement cancelled.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SeqNum UInt32 | |
Tick UInt32 | |
RttSample UInt32 | |
NewSrtt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1168",
"version": "0",
"level": "5",
"task": "1168",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:27:12.440661100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"SeqNum": " 0",
"Tick": " 0",
"RttSample": " 0",
"NewSrtt": " 0"
},
"message": ""
}
Event ID 1169: UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.
#Description
UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes. PID = Pid.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
NumMessages UInt32 | |
NumBytes UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary | |
Pid UInt32 | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1169",
"version": "0",
"level": "4",
"task": "1169",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.078234200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"NumMessages": " 1",
"NumBytes": " 63",
"LocalSockAddrLength": " 28",
"LocalSockAddr": "[::ffff:0:0]:53893",
"RemoteSockAddrLength": " 28",
"RemoteSockAddr": "[::ffff:10.2.10.11]:53",
"Pid": " 228"
},
"message": ""
}
Event ID 1170: UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.
#Description
UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes. PID = Pid.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
NumMessages UInt32 | |
NumBytes UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary | |
Pid UInt32 | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1170",
"version": "0",
"level": "4",
"task": "1170",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.117082900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"NumMessages": " 0",
"NumBytes": " 186",
"LocalSockAddrLength": " 28",
"LocalSockAddr": "[::ffff:10.2.10.21]:53893",
"RemoteSockAddrLength": " 28",
"RemoteSockAddr": "[::ffff:10.2.10.11]:53",
"Pid": " 228"
},
"message": ""
}
Event ID 1171: TCP: connection Tcb delivery Delivery flushing NumBytes bytes Length requested status = RequestStatus.
#Description
TCP: connection Tcb delivery Delivery flushing NumBytes bytes Length requested status = RequestStatus.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1171",
"version": "0",
"level": "5",
"task": "1171",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.593480400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Delivery": "0xFFFF980A15CE6D10",
"Request": "0xFFFF980A11C13950",
"NumBytes": "0x0",
"RequestFlags": " 0",
"Length": "0x2000",
"RequestStatus": "0xC0000120",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": " 0"
},
"message": ""
}
Event ID 1172: TCP: Injecting receive on a shutdown TCB failed.
#Event ID 1173: TCP: connection Tcb delivery Delivery injecting NumBytes bytes delta Length, IsUrgentDelivery = IsUrgentDelivery.
#Description
TCP: connection Tcb delivery Delivery injecting NumBytes bytes delta Length, IsUrgentDelivery = IsUrgentDelivery.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1173",
"version": "0",
"level": "5",
"task": "1173",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:28.315732300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7644"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"Delivery": "0xFFFF980A0E584790",
"Request": "0x0",
"NumBytes": "0x0",
"RequestFlags": " 0",
"Length": "0x70",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": " 0"
},
"message": ""
}
Event ID 1174: TCP: Injecting fin on a shutdown TCB failed.
#Event ID 1175: TCP: connection Tcb delivery Delivery accepting NumBytes bytes.
#Description
TCP: connection Tcb delivery Delivery accepting NumBytes bytes. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1175",
"version": "0",
"level": "5",
"task": "1175",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:22:29.058226900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0x0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "3537945353"
},
"message": ""
}
Event ID 1176: TCP: connection Tcb delivery Delivery delivering FIN.
#Description
TCP: connection Tcb delivery Delivery delivering FIN. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1176",
"version": "0",
"level": "4",
"task": "1176",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:38.731999900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"Delivery": "0xFFFF980A0EEE7790",
"Request": "0x0",
"NumBytes": "0x0",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "2633618840"
},
"message": ""
}
Event ID 1178: TCP: connection Tcb delivery Delivery pushing NumBytes bytes Length requested.
#Description
TCP: connection Tcb delivery Delivery pushing NumBytes bytes Length requested. Delayed push = FullySatisfiedORDelayedPush.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Event ID 1180: TCP: Injecting fin on TCB completed.
#Description
TCP: Injecting fin on TCB completed. TCB = Tcb, Processor = NumBytes.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1180",
"version": "0",
"level": "5",
"task": "1180",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:59.852963300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "13080"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A14CDE010",
"Delivery": "0x0",
"Request": "0x0",
"NumBytes": "0xD",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": " 0"
},
"message": ""
}
Event ID 1181: TCP: connection Tcb delivery Delivery urgent boundary completing NumBytes bytes Length requested.
#Description
TCP: connection Tcb delivery Delivery urgent boundary completing NumBytes bytes Length requested.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Event ID 1182: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress): initiating SYN/RST validation.
#Event ID 1183: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: received RST.
#Event ID 1184: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received RST.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received RST.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
NewState UInt32 | |
RexmitCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1184",
"version": "0",
"level": "4",
"task": "1184",
"opcode": "0",
"keywords": 9223372062624579712,
"time_created": "2026-03-16T00:23:11.140010200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11ae9ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A11AE9AE0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:53002",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.11:445",
"NewState": " 0",
"RexmitCount": " 0"
},
"message": ""
}
Event ID 1185: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received SYN in state NewState.
#Event ID 1186: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting connect attempt, RexmitCount = RexmitCount.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting connect attempt, RexmitCount = RexmitCount.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
NewState UInt32 | |
RexmitCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1186",
"version": "0",
"level": "4",
"task": "1186",
"opcode": "0",
"keywords": 9223372058329612416,
"time_created": "2026-03-15T23:31:42.716275300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FF9CA95F0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.11:51269",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.21:389",
"NewState": " 0",
"RexmitCount": " 1"
},
"message": ""
}
Event ID 1187: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting data, RexmitCount = RexmitCount.
#Event ID 1188: TCP: connection Tcb send keep-alive at SndUna = SndUna.
#Description
TCP: connection Tcb send keep-alive at SndUna = SndUna.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1188",
"version": "0",
"level": "4",
"task": "1188",
"opcode": "0",
"keywords": 9223372058329612416,
"time_created": "2026-03-16T00:21:53.057881700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"SndUna": "2262383926",
"SndMax": " 0"
},
"message": ""
}
Event ID 1189: TCP: connection Tcb, delivery Delivery: delivery state changed from OldDeliveryState to NewDeliveryState.
#Event ID 1190: TCP: connection Tcb delivery Delivery dropping data.
#Description
TCP: connection Tcb delivery Delivery dropping data. TotalBytesEnqueued = NumBytes. Length = Length. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Delivery Pointer | |
Request Pointer | |
NumBytes Pointer | |
RequestFlags UInt32 | |
Length Pointer | |
RequestStatus UInt32 | |
IsUrgentDelivery UInt32 | |
FullySatisfiedORDelayedPush UInt32 | |
RcvNxt UInt32 |
Event ID 1191: TCP: endpoint/connection PortAcquirer acquired port number PortNumber.
#Description
TCP: endpoint/connection PortAcquirer acquired port number PortNumber.
Message #
Fields #
| Name | Description |
|---|---|
PortAcquirer Pointer | |
PortNumber UInt16 | |
WeakReference UInt32 | |
OriginalAcquirer Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1191",
"version": "0",
"level": "4",
"task": "1191",
"opcode": "0",
"keywords": 9223372054034644992,
"time_created": "2026-03-16T00:21:40.119043200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0da8a910-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PortAcquirer": "0xFFFF980A0DA8A910",
"PortNumber": "52999",
"WeakReference": " 0",
"OriginalAcquirer": "0x0"
},
"message": ""
}
Event ID 1192: TCP: connection PortAcquirer attempted to acquire weak reference on port number PortNumber inherited from endpoint OriginalAcquirer.
#Description
TCP: connection PortAcquirer attempted to acquire weak reference on port number PortNumber inherited from endpoint OriginalAcquirer. Successful = WeakReference.
Message #
Fields #
| Name | Description |
|---|---|
PortAcquirer Pointer | |
PortNumber UInt16 | |
WeakReference UInt32 | |
OriginalAcquirer Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1192",
"version": "0",
"level": "4",
"task": "1192",
"opcode": "0",
"keywords": 9223372054034644992,
"time_created": "2026-03-16T00:21:38.719220200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PortAcquirer": "0xFFFF980A0EEE7560",
"PortNumber": "5985",
"WeakReference": " 1",
"OriginalAcquirer": "0xFFFF980A0EF4B580"
},
"message": ""
}
Event ID 1193: TCP: endpoint/connection PortAcquirer released port number PortNumber.
#Description
TCP: endpoint/connection PortAcquirer released port number PortNumber. WeakReference = WeakReference.
Message #
Fields #
| Name | Description |
|---|---|
PortAcquirer Pointer | |
PortNumber UInt16 | |
WeakReference UInt32 | |
OriginalAcquirer Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1193",
"version": "0",
"level": "4",
"task": "1193",
"opcode": "0",
"keywords": 9223372054034644992,
"time_created": "2026-03-16T00:21:38.733428000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PortAcquirer": "0xFFFF980A0EEE7560",
"PortNumber": "5985",
"WeakReference": " 1",
"OriginalAcquirer": "0x0"
},
"message": ""
}
Event ID 1194: TCP: endpoint/connection PortAcquirer replaced base endpoint OriginalAcquirer and acquired reference to port number PortNumber.
#Event ID 1195: TCP: Portpool assigned port number PortNumber with weak references due to port exhaustion.
#Event ID 1196: TCP: connection Tcb BH receive ACK for full size seq.
#Description
TCP: connection Tcb BH receive ACK for full size seq. Seq = SndUna. IsSack = IsSack.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 | |
Reason UnicodeString | |
IsSack UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1196",
"version": "0",
"level": "4",
"task": "1196",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:23:27.217663000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"SndUna": "1228953133",
"SndMax": " 0",
"Reason": "NULL",
"IsSack": " 0"
},
"message": ""
}
Event ID 1197: TCP: connection Tcb flushed SACK state at SndUna = SndUna.
#Event ID 1198: TCP: Connection Tcb entering reassembly at RcvNxt = SndUna.
#Description
TCP: Connection Tcb entering reassembly at RcvNxt = SndUna.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1198",
"version": "0",
"level": "5",
"task": "1198",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:59.839186900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A14CDE010",
"SndUna": "3358248696",
"SndMax": " 0"
},
"message": ""
}
Event ID 1199: TCP: Connection Tcb leaving reassembly at RcvNxt = SndUna.
#Description
TCP: Connection Tcb leaving reassembly at RcvNxt = SndUna.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1199",
"version": "0",
"level": "5",
"task": "1199",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:59.839225300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A14CDE010",
"SndUna": "3358248696",
"SndMax": " 0"
},
"message": ""
}
Event ID 1200: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: Zero window probe timeout expired.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: Zero window probe timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1201: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: FIN-WAIT-2 timeout expired.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: FIN-WAIT-2 timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1202: IP: Interface rundown: Index = IfIndex, Linkspeed = CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType, IP Address = IPv4 Address IPProtocol IPv6 Address.
#Description
IP: Interface rundown: Index = IfIndex, Linkspeed = CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType, IP Address = IPv4 Address IPProtocol IPv6 Address.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CurrLinkSpeed UInt64 | |
IPProtocol UInt32 | |
IPv4Address UInt32 | |
IpAddrLength UInt32 | |
IPv6Address Binary | |
PhysicalMediumType UInt32 | |
CompartmentId UInt32 | |
OldLinkSpeed UInt64 | |
NetworkCategory UInt32 | |
Metric UInt32 | |
Connected UInt32 | |
InternetConnectivityStatus UInt32 | |
Flags UInt64 | |
IsolationId UInt32 | |
NlMtu UInt32 | |
ForwardingTag UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1202",
"version": "4",
"level": "4",
"task": "1202",
"opcode": "0",
"keywords": 9223372586610589840,
"time_created": "2026-03-15T23:26:13.264840100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "15176",
"thread_id": "13152"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 1",
"CurrLinkSpeed": "0",
"IPProtocol": " 4",
"IPv4 Address": "127.0.0.1",
"IpAddrLength": " 0",
"IPv6 Address": "",
"PhysicalMediumType": " 0",
"CompartmentId": " 1",
"OldLinkSpeed": "0",
"NetworkCategory": " 0",
"Metric": " 75",
"Connected": " 1",
"InternetConnectivityStatus": "4294967295",
"Flags": "0x10262102300",
"IsolationId": " 0"
},
"message": ""
}
Event ID 1203: IP: Interface Index = IfIndex, Linkspeed changed to CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType.
#Description
IP: Interface Index = IfIndex, Linkspeed changed to CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CurrLinkSpeed UInt64 | |
IPProtocol UInt32 | |
IPv4Address UInt32 | |
IpAddrLength UInt32 | |
IPv6Address Binary | |
PhysicalMediumType UInt32 | |
CompartmentId UInt32 | |
OldLinkSpeed UInt64 | |
ReceiveLinkSpeed UInt64 | |
MediaConnectState UInt32 |
Event ID 1204: TCP: Connection Tcb flushing reassembly state at RcvNxt = SndUna.
#Event ID 1205: TCPIP: NBL Nbl fell off the receive fast path, Reason: Reason.
#Description
TCPIP: NBL Nbl fell off the receive fast path, Reason: Reason. Protocol = IPTransportProtocol, Family = AddressFamily, Number of NBLs = NblCount. SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address.
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | |
IPTransportProtocol UInt32 | |
AddressFamily UInt32 | |
SourceIPv4Address UInt32 | |
DestIPv4Address UInt32 | |
IPv6SourceIpAddrLength UInt32 | |
IPv6SourceAddress Binary | |
IPv6DestIpAddrLength UInt32 | |
IPv6DestAddress Binary | |
Reason UInt32 | |
NblCount UInt32 | |
IPProtocol UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1205",
"version": "0",
"level": "5",
"task": "1205",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:38.718814700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A1D7C5570",
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"Source IPv4 Address": "10.2.10.11",
"Dest IPv4 Address": "10.2.10.21",
"IPv6SourceIpAddrLength": " 0",
"IPv6 Source Address": "",
"IPv6DestIpAddrLength": " 0",
"IPv6 Dest Address": "",
"Reason": " 17",
"NblCount": " 1",
"IPProtocol": " 4"
},
"message": ""
}
Event ID 1206: TCPIP: NBL Nbl fell off the send fast path, Reason: Reason.
#Description
TCPIP: NBL Nbl fell off the send fast path, Reason: Reason. Protocol = IPTransportProtocol, Family = AddressFamily, Number of NBLs = NblCount. SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address.
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | |
IPTransportProtocol UInt32 | |
AddressFamily UInt32 | |
SourceIPv4Address UInt32 | |
DestIPv4Address UInt32 | |
IPv6SourceIpAddrLength UInt32 | |
IPv6SourceAddress Binary | |
IPv6DestIpAddrLength UInt32 | |
IPv6DestAddress Binary | |
Reason UInt32 | |
NblCount UInt32 | |
IPProtocol UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1206",
"version": "0",
"level": "5",
"task": "1206",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388870500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A11CCA4F0",
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"Source IPv4 Address": "10.2.10.21",
"Dest IPv4 Address": "10.2.20.41",
"IPv6SourceIpAddrLength": " 0",
"IPv6 Source Address": "",
"IPv6DestIpAddrLength": " 0",
"IPv6 Dest Address": "",
"Reason": " 11",
"NblCount": " 1",
"IPProtocol": " 4"
},
"message": ""
}
Event ID 1207: TCP: WSD - TcpWsdEtwPoint Status: Status.
#Description
TCP: WSD - TcpWsdEtwPoint Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
TcpWsdEtwPoint UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1208: TCP: WSD - TcpWsdEtwPoint Status: Status.
#Description
TCP: WSD - TcpWsdEtwPoint Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
TcpWsdEtwPoint UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1209: TCP: WSD - TCB Tcb will use a highly restricted window scale factor due to a TcpWsdEtwPoint.
#Event ID 1210: TCP: WSD - TCB Tcb will use a highly restricted window scale factor due to a TcpWsdEtwPoint.
#Event ID 1211: TCP: WSD - Entry (Processor, Entry) moved from OldState to NewState due to TcpWsdEtwPoint.
#Event ID 1212: TCP: WSD - Profile: Profile State: State Qualified: Qualified EreQualified: EreQualified.
#Event ID 1213: TCP: WSD - Enabled moved from OldEnabledState to NewEnabledState.
#Event ID 1214: TCPIP: Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s) with Local = LocalSockAddr, Remote = RemoteSockAddr.
#Description
TCPIP: Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s) with Local = LocalSockAddr, Remote = RemoteSockAddr. Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | |
AddressFamily UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary | |
Reason UInt32 | |
PacketCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1214",
"version": "0",
"level": "4",
"task": "1214",
"opcode": "0",
"keywords": 9223373694712152192,
"time_created": "2026-03-16T00:21:38.733034500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"LocalSockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:5985",
"RemoteSockAddrLength": " 16",
"RemoteSockAddr": "10.2.10.11:51201",
"Reason": " 20",
"PacketCount": " 1"
},
"message": ""
}
Event ID 1215: TCPIP: Network layer (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s).
#Description
TCPIP: Network layer (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s). SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address. Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | |
AddressFamily UInt32 | |
SourceIPv4Address UInt32 | |
DestIPv4Address UInt32 | |
IPv6SourceIpAddrLength UInt32 | |
IPv6SourceAddress Binary | |
IPv6DestIpAddrLength UInt32 | |
IPv6DestAddress Binary | |
Reason UInt32 | |
PacketCount UInt32 | |
IPProtocol UInt32 | |
SourceAddressLength UInt32 | |
SourceAddress Binary | |
DestAddressLength UInt32 | |
DestAddress Binary | |
IfIndex UInt32 | |
PathDirection UInt32 | |
Nbl Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1215",
"version": "1",
"level": "4",
"task": "1215",
"opcode": "0",
"keywords": 9223373699007119488,
"time_created": "2026-03-15T23:27:04.761762100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "3912",
"thread_id": "13412"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 6",
"AddressFamily": " 23",
"Source IPv4 Address": "0.0.0.0",
"Dest IPv4 Address": "0.0.0.0",
"IPv6SourceIpAddrLength": " 16",
"IPv6 Source Address": "::1",
"IPv6DestIpAddrLength": " 16",
"IPv6 Dest Address": "::1",
"Reason": " 256",
"PacketCount": " 1",
"IPProtocol": " 6",
"SourceAddressLength": " 28",
"SourceAddress": "::1",
"DestAddressLength": " 28",
"DestAddress": "::1",
"IfIndex": " 1",
"PathDirection": " 1"
},
"message": ""
}
Event ID 1216: TCP: MPP NPP Evaluation PhysicalPages = PhysicalPages NonPagedPoolPages = NonPagedPoolPages Current = CurrentWatermark Peak = PeakWatermark Low = HighWatermark High = LowWatermark.
#Description
TCP: MPP NPP Evaluation PhysicalPages = PhysicalPages NonPagedPoolPages = NonPagedPoolPages Current = CurrentWatermark Peak = PeakWatermark Low = HighWatermark High = LowWatermark.
Message #
Fields #
| Name | Description |
|---|---|
PhysicalPages UInt32 | |
NonPagedPoolPages UInt32 | |
CurrentWatermark UInt32 | |
PeakWatermark UInt32 | |
HighWatermark UInt32 | |
LowWatermark UInt32 |
Event ID 1217: TCP: MPP: Episode started.
#Description
TCP: MPP: Episode started. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpisodeStartTick = EpisodeStartTick EpisodeStopTick = EpisodeStopTick Current = CurrentWatermark Low = LowWatermark Reentry = ReentryWatermark.
Message #
Fields #
| Name | Description |
|---|---|
LowNppEventState UInt32 | |
HighNppEventState UInt32 | |
EpisodeStartTick UInt64 | |
EpisodeStopTick UInt64 | |
CurrentWatermark UInt32 | |
LowWatermark UInt32 | |
ReentryWatermark UInt32 |
Event ID 1218: TCP: MPP: Episode ended.
#Description
TCP: MPP: Episode ended. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpisodeStartTick = EpisodeStartTick EpisodeStopTick = EpisodeStopTick Reentry = ReentryWatermark.
Message #
Fields #
| Name | Description |
|---|---|
LowNppEventState UInt32 | |
HighNppEventState UInt32 | |
EpisodeStartTick UInt64 | |
EpisodeStopTick UInt64 | |
ReentryWatermark UInt32 |
Event ID 1219: TCP: MPP: Epoch Epoch started.
#Description
TCP: MPP: Epoch Epoch started. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpochStartTick = EpochStartTick EpochStopTick = EpochStopTick SynDropRate = OldSynDropRate -> NewSynDropRate TcbKillRate = OldTcbKillRate -> NewTcbKillRate CurrentWatermark = CurrentWatermark.
Message #
Fields #
| Name | Description |
|---|---|
Epoch UInt32 | |
LowNppEventState UInt32 | |
HighNppEventState UInt32 | |
EpochStartTick UInt64 | |
EpochStopTick UInt64 | |
OldSynDropRate UInt32 | |
NewSynDropRate UInt32 | |
OldTcbKillRate UInt32 | |
NewTcbKillRate UInt32 | |
CurrentWatermark UInt32 |
Event ID 1220: TCP: MPP: Epoch Epoch ended.
#Description
TCP: MPP: Epoch Epoch ended. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpochStartTick = EpochStartTick EpochStopTick = EpochStopTick SynDropRate = SynDropRate TcbKillRate = TcbKillRate Current = CurrentWatermark.
Message #
Fields #
| Name | Description |
|---|---|
Epoch UInt32 | |
LowNppEventState UInt32 | |
HighNppEventState UInt32 | |
EpochStartTick UInt64 | |
EpochStopTick UInt64 | |
SynDropRate UInt32 | |
TcbKillRate UInt32 | |
CurrentWatermark UInt32 |
Event ID 1221: TCP: Connection Tcb restarting Cwnd.
#Event ID 1222: TCP: Connection Tcb adjust InitalCwnd.
#Event ID 1223: TCP: Connection Tcb committed TemplateType = TemplateType.
#Description
TCP: Connection Tcb committed TemplateType = TemplateType. MinRto = MinRto msec, EnableCwndRestart = EnableCwndRestart, InitialCwnd = InitialCwnd MSS, CongestionAlgorithm = CongestionAlgorithm, MaxDataRetransmissions = MaxDataRetransmissions, DelayedAckTicks = DelayedAckTicks msec, DelayedAckFrequency = DelayedAckFrequency, RACK enabled = Rack, Tail Loss Probe enabled = TailLossProbe.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
TemplateType UInt32 | |
MinRto UInt32 | |
EnableCwndRestart UInt32 | |
InitialCwnd UInt32 | |
CongestionAlgorithm UInt32 | |
MaxDataRetransmissions UInt32 | |
DelayedAckTicks UInt32 | |
DelayedAckFrequency UInt32 | |
Rack UInt32 | |
TailLossProbe UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1223",
"version": "0",
"level": "4",
"task": "1223",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:38.719984100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"TemplateType": " 0",
"MinRto": " 300",
"EnableCwndRestart": " 0",
"InitialCwnd": " 10",
"CongestionAlgorithm": " 5",
"MaxDataRetransmissions": " 5",
"DelayedAckTicks": " 40",
"DelayedAckFrequency": " 2",
"Rack": " 1",
"TailLossProbe": " 1"
},
"message": ""
}
Event ID 1224: TCP: Connection Tcb template changed.
#Description
TCP: Connection Tcb template changed. New template=TemplateType. Context=Context.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
TemplateType UInt32 | |
Context UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1224",
"version": "0",
"level": "5",
"task": "1224",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:38.719121800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"TemplateType": " 0",
"Context": "Initializing Template Accept TCB"
},
"message": ""
}
Event ID 1225: TCP: connection Tcb: End of a round, SndRound = SndRound, Bytes sent = EcnTotalByteCount.
#Description
TCP: connection Tcb: End of a round, SndRound = SndRound, Bytes sent = EcnTotalByteCount. Bytes marked = EcnTotalMarkedCount, ThAck = ThAck, updated EcnAlpha = EcnAlpha.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndRound UInt32 | |
EcnTotalByteCount UInt32 | |
EcnTotalMarkedCount UInt32 | |
ThAck UInt32 | |
EcnAlpha UInt32 |
Event ID 1226: TCP: interface IfIndex: RSC state changed, IPV4 State = StateV4, IPV4 Failure Reason = FailureReasonV4, IPV6 State = StateV6, IPV6 Failure Reason = FailureReasonV6, Event = Event.
#Description
TCP: interface IfIndex: RSC state changed, IPV4 State = StateV4, IPV4 Failure Reason = FailureReasonV4, IPV6 State = StateV6, IPV6 Failure Reason = FailureReasonV6, Event = Event.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
StateV4 UInt32 | |
FailureReasonV4 UInt32 | |
StateV6 UInt32 | |
FailureReasonV6 UInt32 | |
Event UInt32 |
Event ID 1227: TCP: connection Tcb: RSC SCU received.
#Description
TCP: connection Tcb: RSC SCU received. CoalescedSegCount = CoalescedSegCount, DupAckCount = DupAckCount, RscTcpTimestampDelta = RscTcpTimestampDelta, HeaderFlags = HeaderFlags, EcnCePresent = EcnCePresent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
CoalescedSegCount UInt16 | |
DupAckCount UInt16 | |
RscTcpTimestampDelta UInt32 | |
HeaderFlags UInt16 | |
EcnCePresent UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1227",
"version": "0",
"level": "5",
"task": "1227",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:36.016716200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{10708010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A10708010",
"CoalescedSegCount": "2",
"DupAckCount": "0",
"RscTcpTimestampDelta": " 0",
"HeaderFlags": "24",
"EcnCePresent": " 0"
},
"message": ""
}
Event ID 1228: TCPIP: TCB Tcb does not take fast path, Cause: Cause.
#Event ID 1229: TCP: Connection Tcb send queue is idle.
#Description
TCP: Connection Tcb send queue is idle. Cwnd = OldCwnd, Processor = Processor, CurrentTick = CurrentTick, IdleTick = IdleTick.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
OldCwnd UInt32 | |
NewCwnd UInt32 | |
Processor UInt32 | |
CurrentTick UInt32 | |
IdleTick UInt32 | |
Rto UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1229",
"version": "0",
"level": "4",
"task": "1221",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390542000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"OldCwnd": " 2110976",
"NewCwnd": " 0",
"Processor": " 8",
"CurrentTick": "57753291",
"IdleTick": "57753291",
"Rto": " 0"
},
"message": ""
}
Event ID 1230: RSS: Bind notification for AddressFamily on interface InterfaceIndex.
#Event ID 1231: RSS: Bind notification for adapter AdapterIndex.
#Event ID 1232: RSS: ReferenceAdded reference on adapter AdapterIndex.
#Event ID 1233: RSS: adapter AdapterIndex with capabilities CapabilitiesFlags and NumberOfReceiveQueues receive queues.
#Event ID 1234: RSS: adapter AdapterIndex processor group GroupNumber maximum processors MaximumProcessors processor affinity GroupAffinity.
#Description
RSS: adapter AdapterIndex processor group GroupNumber maximum processors MaximumProcessors processor affinity GroupAffinity.
Message #
Fields #
| Name | Description |
|---|---|
AdapterIndex UInt32 | |
GroupNumber UInt16 | |
MaximumProcessors UInt32 | |
GroupAffinity UInt64 | |
AvailableProcessorsSize UInt32 | |
AvailableProcessors Binary |
Event ID 1235: RSS: assigning processor ProcessorIndex from adapter PreviousAdapterIndex to NewAdapterIndex.
#Event ID 1236: RSS: unassigning processor ProcessorIndex from adapter PreviousAdapterIndex.
#Event ID 1237: RSS: adapter AdapterIndex reassigning indirection entry IndirectionIndex from processor OldProcessorIndex to NewProcessorIndex.
#Event ID 1238: RSS: adapter AdapterIndex removing processor ProcessorIndex from its indirection table.
#Event ID 1239: RSS: adapter AdapterIndex changing Setting to Value.
#Event ID 1240: RSS: Failed to FailureDescription on IfIndex InterfaceIndex: Status.
#Description
RSS: Failed to FailureDescription on IfIndex InterfaceIndex: Status.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
FailureDescription UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1241: RSS: bind completed successfully for AddressFamily on interface InterfaceIndex.
#Event ID 1242: RSS: bind completed successfully for adapter AdapterIndex.
#Event ID 1243: RSS: adapter AdapterIndex not supported.
#Event ID 1244: RSS: adapter AdapterIndex indirection table initialized on group GroupNumber with processor set ActiveAffinity.
#Event ID 1245: RSS: Rundown: interface InterfaceIndex with adapter AdapterIndex at port PortNumber.
#Description
RSS: Rundown: interface InterfaceIndex with adapter AdapterIndex at port PortNumber.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
AdapterIndex UInt32 | |
PortNumber UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1245",
"version": "0",
"level": "4",
"task": "1245",
"opcode": "0",
"keywords": 9223372586610591888,
"time_created": "2026-03-16T00:21:34.295777000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{517fdda0-f803-ffff-0600-000000000000}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"InterfaceIndex": " 6",
"AdapterIndex": " 6",
"PortNumber": " 0"
},
"message": ""
}
Event ID 1246: RSS: Rundown: adapter AdapterIndex hash info HashInfo maximum processors MaximumProcessors group GroupNumber affinity GroupAffinity active processors ActiveAffinity active mode: ActiveMode.
#Description
RSS: Rundown: adapter AdapterIndex hash info HashInfo maximum processors MaximumProcessors group GroupNumber affinity GroupAffinity active processors ActiveAffinity active mode: ActiveMode.
Message #
Fields #
| Name | Description |
|---|---|
AdapterIndex UInt32 | |
HashInfo UInt32 | |
MaximumProcessors UInt32 | |
GroupNumber UInt16 | |
GroupAffinity UInt64 | |
ActiveAffinity UInt64 | |
ActiveMode UInt32 | |
IndirectionTableSize UInt32 | |
IndirectionTable Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1246",
"version": "0",
"level": "4",
"task": "1246",
"opcode": "0",
"keywords": 9223372586610591888,
"time_created": "2026-03-15T23:26:13.264909200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0f1f9564-f803-ffff-0400-000000000000}"
},
"execution": {
"process_id": "15176",
"thread_id": "13152"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AdapterIndex": " 4",
"HashInfo": "0xD701",
"MaximumProcessors": " 14",
"GroupNumber": "0",
"GroupAffinity": "0x3FFF",
"ActiveAffinity": "0x3FFF",
"ActiveMode": " 1002",
"IndirectionTableSize": " 128",
"IndirectionTable": "0x000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D0001"
},
"message": ""
}
Event ID 1247: RSS: interface InterfaceIndex support: Capability.
#Event ID 1248: NDKPI Create CQ: RequestContext RequestContext Adapter NdkAdapter CqDepth CqDepth CqNotificationContext CqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.
#Description
NDKPI Create CQ: RequestContext RequestContext Adapter NdkAdapter CqDepth CqDepth CqNotificationContext CqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.
Message #
Fields #
| Name | Description |
|---|---|
NdkAdapter Pointer | |
CqDepth UInt32 | |
CqNotificationContext Pointer | |
AffinityMask UInt64 | |
AffinityGroup UInt16 | |
RequestContext Pointer |
Event ID 1249: NDKPI Create Completion: RequestContext RequestContext Status Status (CompletionType) NdkObjectType NdkObject.
#Description
NDKPI Create Completion: RequestContext RequestContext Status Status (CompletionType) NdkObjectType NdkObject.
Message #
Fields #
| Name | Description |
|---|---|
RequestContext Pointer | |
Status UInt32 | NTSTATUS reference |
NdkObject Pointer | |
CompletionType UInt32 | |
NdkObjectType UInt32 |
Event ID 1250: NDKPI Close NdkObjectType: RequestContext RequestContext NdkObjectType NdkObject.
#Event ID 1251: NDKPI Close Completion: RequestContext RequestContext (CompletionType).
#Event ID 1252: NDKPI Resize CQ: RequestContext RequestContext CQ NdkCq CqDepth CqDepth.
#Event ID 1253: NDKPI Request Completion: RequestContext RequestContext Status Status (CompletionType).
#Description
NDKPI Request Completion: RequestContext RequestContext Status Status (CompletionType).
Message #
Fields #
| Name | Description |
|---|---|
RequestContext Pointer | |
Status UInt32 | NTSTATUS reference |
CompletionType UInt32 |
Event ID 1254: NDKPI Arm CQ: CQ NdkCq ArmType.
#Event ID 1255: NDKPI Result ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext.
#Description
NDKPI Result ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext.
Message #
Fields #
| Name | Description |
|---|---|
NdkCq Pointer | |
Status UInt32 | NTSTATUS reference |
BytesTransferred UInt32 | |
QpContext Pointer | |
RequestContext Pointer | |
ResultIndex Int32 | |
ResultCount Int32 |
Event ID 1256: NDKPI Create MR: RequestContext RequestContext PD NdkPd FastRegister FastRegister.
#Event ID 1257: NDKPI Flush: QP NdkQp.
#Event ID 1258: NDKPI Send (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken Flags Flags.
#Description
NDKPI Send (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | |
RequestContext Pointer | |
SgeAddress Pointer | |
SgeLength UInt32 | |
SgeMemoryRegionToken UInt32 | |
NumSge Int32 | |
Flags UInt32 | |
SgeIndex Int32 |
Event ID 1259: NDKPI Receive (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken.
#Event ID 1260: NDKPI Register MR: RequestContext RequestContext MR NdkMr MDL Mdl Length Length Flags Flags.
#Event ID 1261: NDKPI Deregister MR: RequestContext RequestContext MR NdkObject.
#Event ID 1262: NDKPI Initialize FastRegister MR: RequestContext RequestContext MR NdkMr AdapterPageCount AdapterPageCount RemoteAccess RemoteAccess.
#Event ID 1263: NDKPI Modify SRQ: RequestContext RequestContext SRQ NdkSrq SrqDepth SrqDepth NotifyThreshold NotifyThreshold.
#Event ID 1264: NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SrcAddress SrcSockAddr DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
#Description
NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SrcAddress SrcSockAddr DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | |
NdkQp Pointer | |
SrcSockAddrLength UInt32 | |
SrcSockAddr Binary | |
DestSockAddrLength UInt32 | |
DestSockAddr Binary | |
IRD UInt32 | |
ORD UInt32 | |
RequestContext Pointer | |
NdkSharedEndpoint Pointer | |
PrivateDataLength UInt32 |
Event ID 1265: NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SharedEndpoint NdkSharedEndpoint DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
#Description
NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SharedEndpoint NdkSharedEndpoint DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | |
NdkQp Pointer | |
SrcSockAddrLength UInt32 | |
SrcSockAddr Binary | |
DestSockAddrLength UInt32 | |
DestSockAddr Binary | |
IRD UInt32 | |
ORD UInt32 | |
RequestContext Pointer | |
NdkSharedEndpoint Pointer | |
PrivateDataLength UInt32 |
Event ID 1266: NDKPI CompleteConnect: RequestContext RequestContext Connector NdkConnector DisconnectEventContext DisconnectEventContext.
#Event ID 1267: NDKPI Accept: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
#Description
NDKPI Accept: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | |
NdkQp Pointer | |
IRD UInt32 | |
ORD UInt32 | |
DisconnectEventContext Pointer | |
RequestContext Pointer | |
PrivateDataLength UInt32 |
Event ID 1268: NDKPI Disconnect: RequestContext RequestContext Connector NdkObject.
#Event ID 1269: NDKPI Listen: RequestContext RequestContext Listener NdkListener Address SockAddr.
#Event ID 1270: NDKPI Create MW: RequestContext RequestContext PD NdkObject.
#Event ID 1271: NDKPI Create SRQ: RequestContext RequestContext PD NdkPd SrqDepth SrqDepth MaxReceiveRequestSge MaxReceiveRequestSge NotifyThreshold NotifyThreshold SrqNotificationContext SrqNotificationContext Af...
#Description
NDKPI Create SRQ: RequestContext RequestContext PD NdkPd SrqDepth SrqDepth MaxReceiveRequestSge MaxReceiveRequestSge NotifyThreshold NotifyThreshold SrqNotificationContext SrqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.
Message #
Fields #
| Name | Description |
|---|---|
NdkPd Pointer | |
SrqDepth UInt32 | |
MaxReceiveRequestSge UInt32 | |
NotifyThreshold UInt32 | |
SrqNotificationContext Pointer | |
AffinityMask UInt64 | |
AffinityGroup UInt16 | |
RequestContext Pointer |
Event ID 1272: NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq QPContext QPContext ReceiveQueueDepth ReceiveQueueDepth InitiatorQueueDepth InitiatorQueueDepth M...
#Description
NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq QPContext QPContext ReceiveQueueDepth ReceiveQueueDepth InitiatorQueueDepth InitiatorQueueDepth MaxReceiveRequestSge MaxReceiveRequestSge MaxInitiatorRequestSge MaxInitiatorRequestSge.
Message #
Fields #
| Name | Description |
|---|---|
NdkPd Pointer | |
ReceiveCq Pointer | |
InitiatorCq Pointer | |
QPContext Pointer | |
ReceiveQueueDepth UInt32 | |
InitiatorQueueDepth UInt32 | |
MaxReceiveRequestSge UInt32 | |
MaxInitiatorRequestSge UInt32 | |
RequestContext Pointer | |
NdkSrq Pointer |
Event ID 1273: NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq SRQ NdkSrq QPContext QPContext InitiatorQueueDepth InitiatorQueueDepth MaxInitiatorRequestSge Max...
#Description
NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq SRQ NdkSrq QPContext QPContext InitiatorQueueDepth InitiatorQueueDepth MaxInitiatorRequestSge MaxInitiatorRequestSge.
Message #
Fields #
| Name | Description |
|---|---|
NdkPd Pointer | |
ReceiveCq Pointer | |
InitiatorCq Pointer | |
QPContext Pointer | |
ReceiveQueueDepth UInt32 | |
InitiatorQueueDepth UInt32 | |
MaxReceiveRequestSge UInt32 | |
MaxInitiatorRequestSge UInt32 | |
RequestContext Pointer | |
NdkSrq Pointer |
Event ID 1274: NDKPI Create PD: RequestContext RequestContext Adapter NdkObject.
#Event ID 1275: NDKPI Create SharedEndpoint: RequestContext RequestContext Adapter NdkListener Address SockAddr.
#Event ID 1276: NDKPI Create Connector: RequestContext RequestContext Adapter NdkObject.
#Event ID 1277: NDKPI Create Listener: RequestContext RequestContext Adapter NdkAdapter ConnectEventContext ConnectEventContext.
#Event ID 1278: NDKPI Build LAM: RequestContext RequestContext Adapter NdkAdapter MDL Mdl Length Length LAMBuffer LAMBuffer LAMBufferSize LAMBufferSize.
#Event ID 1279: NDKPI Release LAM: Adapter NdkAdapter LAMBuffer LAMBuffer.
#Event ID 1280: NDKPI CQ Notification Callback: CqNotificationContext CqNotificationContext CqStatus CqStatus.
#Event ID 1281: NDKPI SRQ Notification Callback: SrqNotificationContext SrqNotificationContext SrqStatus SrqStatus.
#Event ID 1282: NDKPI Disconnect Event Callback: DisconnectEventContext DisconnectEventContext.
#Event ID 1283: NDKPI Connect Event Callback: ConnectEventContext ConnectEventContext Connector NdkConnector.
#Event ID 1284: NDKPI Got TokenType Token Token from NdkObjectType NdkObject.
#Event ID 1285: NDKPI Got SockAddrType Address SockAddr from NdkObjectType NdkObject.
#Event ID 1286: NDKPI SockAddrType Address query failure Status on NdkObjectType NdkObject.
#Description
NDKPI SockAddrType Address query failure Status on NdkObjectType NdkObject.
Message #
Fields #
| Name | Description |
|---|---|
NdkObject Pointer | |
NdkObjectType UInt32 | |
SockAddrType UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1287: NDKPI Reject: Connector NdkConnector PrivateDataLength PrivateDataLength Status Status.
#Description
NDKPI Reject: Connector NdkConnector PrivateDataLength PrivateDataLength Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | |
PrivateDataLength UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1288: NDKPI Get Connect Data: Connector NdkConnector IRD IRD ORD ORD PrivateDataLength PrivateDataLength Status Status.
#Description
NDKPI Get Connect Data: Connector NdkConnector IRD IRD ORD ORD PrivateDataLength PrivateDataLength Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | |
IRD UInt32 | |
ORD UInt32 | |
PrivateDataLength UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1289: NDKPI Work Request Inline Failure: RequestContext RequestContext QP NdkQp Status Status.
#Description
NDKPI Work Request Inline Failure: RequestContext RequestContext QP NdkQp Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | |
RequestContext Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 1290: NDKPI Bind: RequestContext RequestContext QP NdkQp MR NdkMr MW NdkMw VirtualAddress VirtualAddress Length Length Flags Flags.
#Event ID 1291: NDKPI FastRegister: RequestContext RequestContext QP NdkQp MR NdkMr AdapterPageCount AdapterPageCount AdapterPageArray AdapterPageArray FBO FBO Length Length BaseVirtualAddress BaseVirtualAddress F...
#Description
NDKPI FastRegister: RequestContext RequestContext QP NdkQp MR NdkMr AdapterPageCount AdapterPageCount AdapterPageArray AdapterPageArray FBO FBO Length Length BaseVirtualAddress BaseVirtualAddress Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | |
RequestContext Pointer | |
NdkMr Pointer | |
AdapterPageCount UInt32 | |
AdapterPageArray Pointer | |
FBO UInt32 | |
Length UInt64 | |
BaseVirtualAddress Pointer | |
Flags UInt32 |
Event ID 1292: NDKPI Invalidate: RequestContext RequestContext QP NdkQp NdkObjectType NdkObject Flags Flags.
#Event ID 1293: NDKPI Read (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
#Description
NDKPI Read (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | |
RequestContext Pointer | |
SgeAddress Pointer | |
SgeLength UInt32 | |
SgeMemoryRegionToken UInt32 | |
NumSge Int32 | |
Flags UInt32 | |
SgeIndex Int32 | |
RemoteAddress UInt64 | |
RemoteToken UInt32 |
Event ID 1294: NDKPI Write (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
#Description
NDKPI Write (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | |
RequestContext Pointer | |
SgeAddress Pointer | |
SgeLength UInt32 | |
SgeMemoryRegionToken UInt32 | |
NumSge Int32 | |
Flags UInt32 | |
SgeIndex Int32 | |
RemoteAddress UInt64 | |
RemoteToken UInt32 |
Event ID 1295: NDKPI SRQ Receive (SGE SgeIndex/NumSge): RequestContext RequestContext SRQ NdkSrq SGE SgeAddress/SgeLength/SgeMemoryRegionToken.
#Description
NDKPI SRQ Receive (SGE SgeIndex/NumSge): RequestContext RequestContext SRQ NdkSrq SGE SgeAddress/SgeLength/SgeMemoryRegionToken.
Message #
Fields #
| Name | Description |
|---|---|
NdkSrq Pointer | |
RequestContext Pointer | |
SgeAddress Pointer | |
SgeLength UInt32 | |
SgeMemoryRegionToken UInt32 | |
NumSge Int32 | |
Flags UInt32 | |
SgeIndex Int32 |
Event ID 1296: NDKPI SRQ Work Request Inline Failure: RequestContext RequestContext SRQ NdkSrq Status Status.
#Description
NDKPI SRQ Work Request Inline Failure: RequestContext RequestContext SRQ NdkSrq Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkSrq Pointer | |
RequestContext Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 1297: NDKPI Open Adapter: InterfaceIndex InterfaceIndex Adapter NdkAdapter Status Status.
#Description
NDKPI Open Adapter: InterfaceIndex InterfaceIndex Adapter NdkAdapter Status Status.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
NdkAdapter Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 1298: NDKPI Close Adapter (Enter): Adapter NdkAdapter.
#Event ID 1299: NDKPI Close Adapter (Exit): Adapter NdkAdapter.
#Event ID 1300: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) exists.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) exists. State = State. PID = Pid.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
State UInt32 | |
Pid UInt32 | |
ProcessStartKey UInt64 | |
SendTrackerEnabled UInt32 | |
RcvBufSet UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1300",
"version": "2",
"level": "4",
"task": "1300",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-16T00:21:34.294712000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1cf5fec0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1CF5FEC0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52992",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.11:49669",
"State": " 10",
"Pid": " 0",
"ProcessStartKey": "0",
"SendTrackerEnabled": " 0"
},
"message": ""
}
Event ID 1301: NDKPI Interface Event: InterfaceIndex InterfaceIndex, NDK-Operational NDKOperational, EventDescription (StatusCode).
#Description
NDKPI Interface Event: InterfaceIndex InterfaceIndex, NDK-Operational NDKOperational, EventDescription (StatusCode).
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
EventDescription UInt32 | |
NDKOperational UInt32 | |
StatusCode UInt32 | NTSTATUS reference |
Event ID 1302: Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName.
#Description
Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName. Protocol: Protocol. Destination MAC address: DestDLAddress. Source: SrcAddress : SrcPort, Destination: DestAddress : DestPort.
Message #
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | |
PatternFriendlyName UnicodeString | |
DlAddrLength UInt32 | |
SrcDLAddress Binary | |
DestDLAddress Binary | |
SrcAddress UInt32 | |
DestAddress UInt32 | |
Protocol UInt32 | Known values
|
SrcPort UInt16 | |
DestPort UInt16 |
Event ID 1302: Network adapter Luid .
#Description
Network adapter Luid received a wake packet matching pattern . Protocol: . Destination MAC address: . Source: : , Destination: : .
Message #
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | |
PatternFriendlyName UnicodeString | |
DlAddrLength UInt32 | |
SrcDLAddress Binary | |
DestDLAddress Binary | |
SrcAddress UInt32 | |
DestAddress UInt32 | |
Protocol UInt32 | Known values
|
SrcPort UInt16 | |
DestPort UInt16 |
Event ID 1303: Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName.
#Description
Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName. Protocol: Protocol. Destination MAC address: DestDLAddress. Source: SrcAddress : SrcPort, Destination DestAddress : DestPort.
Message #
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | |
PatternFriendlyName UnicodeString | |
DlAddrLength UInt32 | |
SrcDLAddress Binary | |
DestDLAddress Binary | |
IpAddrLength UInt32 | |
SrcAddress Binary | |
DestAddress Binary | |
Protocol UInt32 | Known values
|
SrcPort UInt16 | |
DestPort UInt16 |
Event ID 1303: Network adapter Luid .
#Description
Network adapter Luid received a wake packet matching pattern . Protocol: . Destination MAC address: . Source: : , Destination : .
Message #
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | |
PatternFriendlyName UnicodeString | |
DlAddrLength UInt32 | |
SrcDLAddress Binary | |
DestDLAddress Binary | |
IpAddrLength UInt32 | |
SrcAddress Binary | |
DestAddress Binary | |
Protocol UInt32 | Known values
|
SrcPort UInt16 | |
DestPort UInt16 |
Event ID 1304: TCP: Connection Tcb: Silent Mode SilentModeEvent Context Context.
#Event ID 1305: TCP: Connection Tcb notification channel request.
#Description
TCP: Connection Tcb notification channel request. NcmContext = NcmContext, TCB State = State, PID = Pid, IsLoopback = IsLoopback, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NcmContext Pointer | |
State UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1306: TCP: Connection Tcb query notification channel status request.
#Description
TCP: Connection Tcb query notification channel status request. NcmContext = NcmContext, PID = Pid, Channel Status = ChannelStatus, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NcmContext Pointer | |
State UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1307: TCP: Connection Tcb notification channel request processed.
#Description
TCP: Connection Tcb notification channel request processed. NcmContext = NcmContext, PID = Pid, Status = Status PushNotificationId = PushNotificationGuid.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NcmContext Pointer | |
Pid UInt32 | |
Status UInt32 | NTSTATUS reference |
PushNotificationGuid GUID |
Event ID 1308: TCP: Connection Tcb notification channel signal event.
#Description
TCP: Connection Tcb notification channel signal event. NcmContext = NcmContext, PID = Pid, RcvNxt = RcvNxt, Delivered Data = Delivered, Indicated Data = Indicated, FinalEvent = FinalEvent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NcmContext Pointer | |
Pid UInt32 | |
RcvNxt UInt32 | |
Delivered UInt32 | |
Indicated UInt32 | |
FinalEvent UInt32 |
Event ID 1309: TCP: Connection Tcb notification channel detached.
#Description
TCP: Connection Tcb notification channel detached. NcmContext = NcmContext, TCB State = State. Cleanup NcmContext = IsLoopback.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NcmContext Pointer | |
State UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1310: TCP: Connection Tcb notification channel unlinked.
#Description
TCP: Connection Tcb notification channel unlinked. TCB State = State.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NcmContext Pointer | |
State UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1311: TCP: Connection Tcb notification channel wake pattern plumbing.
#Description
TCP: Connection Tcb notification channel wake pattern plumbing. SystemReserved = SystemReserved, Wake-on-Lan Handle = WolHandle, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SystemReserved UInt32 | |
WolHandle UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1312: TCP: Connection Tcb notification channel wake pattern deplumbing.
#Description
TCP: Connection Tcb notification channel wake pattern deplumbing. Wake-on-Lan Handle = WolHandle, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SystemReserved UInt32 | |
WolHandle UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1313: TCPIP: Interface index InterfaceIndex wake pattern properties.
#Description
TCPIP: Interface index InterfaceIndex wake pattern properties. AOAC capable = AoAcCapable, Bitmap pattern supported = BitmapPatternSupported, ARP/ND offload supported = ARPNDOffloadSupported, IP address = IPv4Address IPProtocol IPv6Address wake ready = IPAddressWakeReady, Wol handle = WolHandle, pattern priority = PhysicalMediumType, interface medium = IpAddrLength, Status = Status, Has been AOAC capable = HasBeenAoAcCapable.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
AoAcCapable UInt32 | |
BitmapPatternSupported UInt32 | |
ARPNDOffloadSupported UInt32 | |
IPAddressWakeReady UInt32 | |
PatternPriority UInt32 | |
PhysicalMediumType UInt32 | |
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 | |
Status UInt32 | NTSTATUS reference |
HasBeenAoAcCapable UInt32 | |
WolHandle UInt32 |
Event ID 1314: NDKPI Control CQ Interrupt Moderation: CQ NdkCq Interval ModerationInterval Count ModerationCount Status Status.
#Description
NDKPI Control CQ Interrupt Moderation: CQ NdkCq Interval ModerationInterval Count ModerationCount Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkCq Pointer | |
ModerationInterval UInt32 | |
ModerationCount UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1315: TCP: Connection Tcb notification channel request processing.
#Description
TCP: Connection notification channel request processing. IsRedirected = , WfpFailure = , Status = , WaitStatus = , Local IP address = , Remote IP address = Local Port = , Remote Port = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
IsRedirected UInt32 | |
WfpFailure UInt32 | |
Status UInt32 | NTSTATUS reference |
WaitStatus UInt32 | |
IpAddrLength UInt32 | |
LocalIPv4Address UInt32 | |
LocalIPv6Address Binary | |
IPProtocol UInt32 | |
RemoteIPv4Address UInt32 | |
RemoteIPv6Address Binary | |
SrcPort UInt16 | |
DestPort UInt16 |
Event ID 1316: IP: IP address lifetime = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, CurrentTime = CurrentTime Old BaseTime = OldBaseTime Old ValidTime = OldValidTime New Bas...
#Description
IP: IP address lifetime = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, CurrentTime = CurrentTime Old BaseTime = OldBaseTime Old ValidTime = OldValidTime New BaseTime = NewBaseTime New ValidTime = NewValidTime.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 | |
CurrentTime UInt32 | |
OldBaseTime UInt32 | |
OldValidTime UInt32 | |
OldPreferredTime UInt32 | |
NewBaseTime UInt32 | |
NewValidTime UInt32 | |
NewPreferredTime UInt32 | |
InterfaceGuid GUID | |
IpAddressLifetimeChangeReason UInt32 |
Event ID 1317: TCP: Repartition event Event (Type) OldPartitionCount.
#Event ID 1318: Component PowerStateTransition on processor IndicatingProcessor at Tick = CurrentTick Time = CurrentTime.
#Event ID 1319: Component timer rescheduled by processor Indicating Processor for processor Target Processor at Tick = Current Tick to Tick = Next Expiration Tick, OldScheduledExpiration = Old Scheduled Expiration...
#Description
Component timer rescheduled by processor Indicating Processor for processor Target Processor at Tick = Current Tick to Tick = Next Expiration Tick, OldScheduledExpiration = Old Scheduled Expiration NewScheduledExpiration = New Scheduled Expiration DueTime = Due Time Aperiodic = Aperiodic.
Message #
Fields #
| Name | Description |
|---|---|
Component UInt32 | |
IndicatingProcessor UInt32 | |
TargetProcessor UInt32 | |
CurrentTick UInt32 | |
NextExpirationTick UInt32 | |
DueTime Int64 | |
Aperiodic UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1319",
"version": "0",
"level": "5",
"task": "1460",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:34.388840200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Component": " 1",
"Indicating Processor": " 9",
"Target Processor": " 10",
"Current Tick": "57753289",
"Next Expiration Tick": "57753299",
"Old Scheduled Expiration": "577539799250",
"New Scheduled Expiration": "577532789097",
"Due Time": "-100000",
"Aperiodic": " 1"
},
"message": ""
}
Event ID 1320: Component timer fired on processor Target Processor at Tick = Current Tick, was scheduled for = Next Expiration.
#Description
Component timer fired on processor Target Processor at Tick = Current Tick, was scheduled for = Next Expiration.
Message #
Fields #
| Name | Description |
|---|---|
Component UInt32 | |
TargetProcessor UInt32 | |
CurrentTick UInt32 | |
NextExpiration UInt32 | |
ExternalTrigger UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1320",
"version": "0",
"level": "5",
"task": "1461",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:34.401656600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Component": " 1",
"Target Processor": " 10",
"Current Tick": "57753302",
"Next Expiration": "57753299",
"Current Interrupt Time": "577532821643",
"Scheduled Expiration Time": "577532789097",
"External Trigger": " 0"
},
"message": ""
}
Event ID 1321: IP: Connecting interface InterfaceIndex, trace = TraceString.
#Event ID 1322: IP: Limited link connectivity set on interface InterfaceIndex, trace = TraceString.
#Event ID 1323: IP: Limited link connectivity reset on interface InterfaceIndex, trace = TraceString.
#Event ID 1324: IP: Neighbor with IpAddress = IP Address DlAddress = DL Address on Interface = Interface changed state from Old Neighbor State to New Neighbor State due to Event = Neighbor Event.
#Description
IP: Neighbor with IpAddress = IP Address DlAddress = DL Address on Interface = Interface changed state from Old Neighbor State to New Neighbor State due to Event = Neighbor Event.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
IpAddrLength UInt32 | |
IPAddress Binary | |
DlAddrLength UInt32 | |
DLAddress Binary | |
OldNeighborState UInt32 | |
NewNeighborState UInt32 | |
NeighborEvent UInt32 | |
CompartmentId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1324",
"version": "1",
"level": "4",
"task": "1324",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:22:30.711141200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Interface": " 6",
"IpAddrLength": " 16",
"IP Address": "10.2.10.11",
"DlAddrLength": " 6",
"DL Address": "0xBC241141F258",
"Old Neighbor State": " 5",
"New Neighbor State": " 2",
"Neighbor Event": " 9",
"CompartmentId": " 1"
},
"message": ""
}
Event ID 1325: IP: Neighbor Event on Interface = Interface from SourceIpAddress = Source IP Address for TargetIpAddress = Target IP Address.
#Description
IP: Neighbor Event on Interface = Interface from SourceIpAddress = Source IP Address for TargetIpAddress = Target IP Address.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
IpAddrLength UInt32 | |
SourceIPAddress Binary | |
TargetIPAddress Binary | |
NeighborEvent UInt32 | |
CompartmentId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1325",
"version": "1",
"level": "5",
"task": "1325",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:21:59.242716700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Interface": " 6",
"IpAddrLength": " 16",
"Source IP Address": "10.2.10.254",
"Target IP Address": "10.2.10.21",
"Neighbor Event": " 12",
"CompartmentId": " 1"
},
"message": ""
}
Event ID 1326: IP: Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName.
#Description
IP: Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName (Rule Rule.RuleExtension).
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | |
PreferredSourceIPAddress Binary | |
NonPreferredSourceIPAddress Binary | |
DestinationIPAddress Binary | |
CompartmentId UInt32 | |
Rule UInt32 | |
RuleExtension UInt32 | |
RuleName UInt32 |
Event ID 1327: IP: Address pair (Preferred Source IP Address, Preferred Destination IP Address) is preferred over (Non-Preferred Source IP Address, Non-Preferred Destination IP Address) by SortOptions = Sort Opti...
#Description
IP: Address pair (Preferred Source IP Address, Preferred Destination IP Address) is preferred over (Non-Preferred Source IP Address, Non-Preferred Destination IP Address) by SortOptions = Sort Option, Rule = Rule Type Rule Major.Rule Minor.
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | |
PreferredSourceIPAddress Binary | |
PreferredDestinationIPAddress Binary | |
NonPreferredSourceIPAddress Binary | |
NonPreferredDestinationIPAddress Binary | |
SortOption UInt32 | |
RuleType AnsiString | |
RuleMajor UInt32 | |
RuleMinor UInt32 | |
RuleName UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1327",
"version": "1",
"level": "5",
"task": "1327",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:23:59.745142800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "1992",
"thread_id": "6452"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IpAddrLength": " 28",
"Preferred Source IP Address": "::ffff:10.2.10.21",
"Preferred Destination IP Address": "::ffff:192.228.79.201",
"Non-Preferred Source IP Address": "::",
"Non-Preferred Destination IP Address": "2001:478:65::53",
"Sort Option": " 0",
"Rule Type": "D",
"Rule Major": " 1",
"Rule Minor": " 0",
"RuleName": " 16"
},
"message": ""
}
Event ID 1328: NDKPI ResultEx ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext Type Type TypeSpecific TypeSpecificCompletionOutput.
#Description
NDKPI ResultEx ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext Type Type TypeSpecific TypeSpecificCompletionOutput.
Message #
Fields #
| Name | Description |
|---|---|
NdkCq Pointer | |
Status UInt32 | NTSTATUS reference |
BytesTransferred UInt32 | |
QpContext Pointer | |
RequestContext Pointer | |
ResultIndex Int32 | |
ResultCount Int32 | |
Type UInt32 | |
TypeSpecificCompletionOutput UInt64 | |
ProviderErrorCode UInt32 |
Event ID 1329: NDKPI SendInvalidate (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteToken RemoteToken Flags Flags.
#Description
NDKPI SendInvalidate (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteToken RemoteToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | |
RequestContext Pointer | |
SgeAddress Pointer | |
SgeLength UInt32 | |
SgeMemoryRegionToken UInt32 | |
NumSge Int32 | |
Flags UInt32 | |
SgeIndex Int32 | |
RemoteToken UInt32 |
Event ID 1330: TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.
#Description
TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SndWnd UInt32 | |
BytesAcked UInt32 | |
SeqNo UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1330",
"version": "0",
"level": "4",
"task": "1071",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390572700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Cwnd": " 2110976",
"SndWnd": " 2110976",
"BytesAcked": " 1303",
"SeqNo": "2307521250"
},
"message": ""
}
Event ID 1331: TCP: connection Tcb: CTCP Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.
#Event ID 1332: TCP: connection Tcb: TCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
#Description
TCP: connection Tcb: TCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SndWnd UInt32 | |
BytesSent UInt32 | |
SeqNo UInt32 | |
SRtt UInt32 | |
RttVar UInt32 | |
RTO UInt32 | |
RcvWnd UInt32 | |
PacingRate UInt32 | |
TcpState UInt32 | |
CongestionState UInt32 | |
SndUna UInt32 | |
SndMax UInt32 | |
RecoveryMax UInt32 | |
RcvBufSet UInt32 | |
MaxRcvBuf UInt32 | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1332",
"version": "1",
"level": "4",
"task": "1073",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.266633700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7af7e0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"Cwnd": " 1705088",
"SndWnd": " 1705088",
"BytesSent": " 0",
"SeqNo": "644684595",
"SRtt": " 596",
"RttVar": " 279",
"RTO": " 60",
"RcvWnd": " 261882"
},
"message": ""
}
Event ID 1333: TCP: connection Tcb: TCP CTCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
#Description
TCP: connection Tcb: TCP CTCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SndWnd UInt32 | |
BytesSent UInt32 | |
SeqNo UInt32 | |
SRtt UInt32 | |
RttVar UInt32 | |
RTO UInt32 | |
RcvWnd UInt32 |
Event ID 1334: UDP: Endpoint UdpEndpoint notification channel request.
#Description
UDP: Endpoint UdpEndpoint notification channel request. NcmContext = NcmContext, Endpoint State = Activated, PID = Pid, IsLoopback = IsLoopback, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | |
NcmContext Pointer | |
Activated UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1335: UDP: Endpoint UdpEndpoint query notification channel status request.
#Description
UDP: Endpoint UdpEndpoint query notification channel status request. NcmContext = NcmContext, Endpoint State = Activated, PID = Pid, Channel Status = ChannelStatus, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | |
NcmContext Pointer | |
Activated UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1336: UDP: Endpoint UdpEndpoint notification channel request processed.
#Description
UDP: Endpoint UdpEndpoint notification channel request processed. NcmContext = NcmContext, PID = Pid, Status = Status PushNotificationId = PushNotificationGuid.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | |
NcmContext Pointer | |
Pid UInt32 | |
Status UInt32 | NTSTATUS reference |
PushNotificationGuid GUID |
Event ID 1337: UDP: Endpoint UdpEndpoint notification channel signal event.
#Event ID 1338: UDP: Endpoint UdpEndpoint notification channel detached.
#Description
UDP: Endpoint UdpEndpoint notification channel detached. NcmContext = NcmContext, Endpoint State = Activated.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | |
NcmContext Pointer | |
Activated UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1339: UDP: Endpoint UdpEndpoint notification channel unlinked.
#Description
UDP: Endpoint UdpEndpoint notification channel unlinked. Endpoint State = Activated.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | |
NcmContext Pointer | |
Activated UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
ChannelStatus UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1340: UDP: Endpoint UdpEndpoint notification channel request processing.
#Description
UDP: Endpoint UdpEndpoint notification channel request processing. Local IP address = LocalIPv4Address IPProtocol LocalIPv6Address, Local Port = SrcPort.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | |
IpAddrLength UInt32 | |
LocalIPv4Address UInt32 | |
LocalIPv6Address Binary | |
IPProtocol UInt32 | |
SrcPort UInt16 |
Event ID 1341: TCP: connection Tcb: Rtt sample recorded RttSample SRTT SRTT RttVar RttVar.
#Description
TCP: connection Tcb: Rtt sample recorded RttSample SRTT SRTT RttVar RttVar.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
RttSample UInt32 | |
RttVar UInt32 | |
SRTT UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1341",
"version": "0",
"level": "5",
"task": "1070",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390489700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"RttSample": " 1632",
"RttVar": " 544",
"SRTT": " 1626"
},
"message": ""
}
Event ID 1342: TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.
#Event ID 1343: TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo.
#Description
TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
DupAckCount UInt32 | |
SeqNo UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1343",
"version": "0",
"level": "4",
"task": "1072",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.488225900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Cwnd": " 16734",
"SSThresh": "4294967295",
"DupAckCount": " 1",
"SeqNo": "155002622"
},
"message": ""
}
Event ID 1344: TCP: CTCP Duplicate Ack event.
#Event ID 1345: TCP: connection Tcb: Spurious timeout at Seq = SeqNo.
#Event ID 1346: TCP: connection Tcb spurious RTO detection initiated at SeqNo.
#Event ID 1347: TCP: connection Tcb spurious RTO detection terminated at SeqNo.
#Event ID 1348: TCP: CTCP DataTransferTimeout event.
#Event ID 1349: TCP: CTCP Spurious timeout event.
#Event ID 1350: TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
#Description
TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1350",
"version": "0",
"level": "4",
"task": "1082",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-15T23:27:12.440659500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"Cwnd": " 15414",
"SSThresh": " 15414"
},
"message": ""
}
Event ID 1351: TCP: connection Tcb: Send Retransmit round with SndUna = SndUna, Round = RexmitCount, SRTT = SRTT, RTO = RTO.
#Description
TCP: connection Tcb: Send Retransmit round with SndUna = SndUna, Round = RexmitCount, SRTT = SRTT, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
RexmitCount UInt32 | |
SRTT UInt32 | |
RTO UInt32 | |
SndMax UInt32 | |
RecoveryMax UInt32 | |
TcpState UInt32 | |
CongestionState UInt32 | |
Frto UInt32 | |
TotalRT UInt32 | |
MaxRT UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1351",
"version": "0",
"level": "4",
"task": "1077",
"opcode": "0",
"keywords": 9223372041149743232,
"time_created": "2026-03-15T23:31:42.716273800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FF9CA95F0",
"SndUna": "2098991634",
"RexmitCount": " 1",
"SRTT": " 3000",
"RTO": " 2000"
},
"message": ""
}
Event ID 1352: TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa...
#Description
TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa \ NonRecovDa NonRecovDaEpisodes NonRecovDaEpisodes DupAcksIn DupAcksIn BytesRetrans BytesRetrans Timeouts Timeouts SpuriousRtoDetections SpuriousRtoDetections FastRetran FastRetran MaxSsthresh MaxSsthresh MaxSsCwnd MaxSsCwnd \ MaxCaCwnd MaxCaCwnd SndLimTransRwin SndLimTransRwin SndLimTimeRwin SndLimTimeRwin SndLimBytesRwin SndLimBytesRwin SndLimTransCwnd SndLimTransCwnd SndLimTimeCwnd SndLimTimeCwnd SndLimBytesCwnd SndLimBytesCwnd \ SndLimTransSnd SndLimTransSnd SndLimTimeSnd SndLimTimeRSnd SndLimBytesSnd SndLimBytesRSnd.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
DataBytesOut UInt64 | |
DataBytesIn UInt64 | |
DataSegmentsOut UInt64 | |
DataSegmentsIn UInt64 | |
SegmentsOut UInt64 | |
SegmentsIn UInt64 | |
NonRecovDa UInt32 | |
NonRecovDaEpisodes UInt32 | |
DupAcksIn UInt32 | |
BytesRetrans UInt32 | |
Timeouts UInt32 | |
SpuriousRtoDetections UInt32 | |
FastRetran UInt32 | |
MaxSsthresh UInt32 | |
MaxSsCwnd UInt32 | |
MaxCaCwnd UInt32 | |
SndLimTransRwin UInt32 | |
SndLimTimeRwin UInt32 | |
SndLimBytesRwin UInt64 | |
SndLimTransCwnd UInt32 | |
SndLimTimeCwnd UInt32 | |
SndLimBytesCwnd UInt64 | |
SndLimTransSnd UInt32 | |
SndLimTimeRSnd UInt32 | |
SndLimBytesRSnd UInt64 |
Event ID 1353: TCPIP: Message AllocationObjectString Param1 Param2 Param3 Param4.
#Event ID 1354: TCP: Connection Tcb SACK updated SndUna SndUna SndMax SndMax SackCount SackCount SackBytes SackBytes SackInFlight SackInFlight SackIsLost SackIsLost.
#Event ID 1355: TCP: TCB Tcb Requires address based pattern = RequireAddressCoalescing LocalPort = LocalPort RtcPortRange = [RtcStartPort, RtcEndPort] Status = Status.
#Description
TCP: TCB Tcb Requires address based pattern = RequireAddressCoalescing LocalPort = LocalPort RtcPortRange = [RtcStartPort, RtcEndPort] Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
RequireAddressCoalescing UInt32 | |
LocalPort UInt16 | |
RtcStartPort UInt16 | |
RtcEndPort UInt16 | |
Status UInt32 | NTSTATUS reference |
Event ID 1356: TCP: Rtc Port Range Assignment.
#Event ID 1357: TCPIP has failed a RequestType request from LocalAddress to RemoteAddress on endpoint TcbOrEndpoint owned by process ProcessId with Status since network interface InterfaceIndex is in low-power mode.
#Description
TCPIP has failed a RequestType request from LocalAddress to RemoteAddress on endpoint TcbOrEndpoint owned by process ProcessId with Status since network interface InterfaceIndex is in low-power mode.
Message #
Fields #
| Name | Description |
|---|---|
RequestType UInt32 | |
TcbOrEndpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
InterfaceIndex UInt32 | |
ProcessStartKey UInt64 |
Event ID 1358: IP: Interface configuration updated on interface InterfaceIndex property Property value Value event InterfaceUpdateEvent.
#Event ID 1359: TCP: Connection Tcb notification channel unmark request.
#Description
TCP: Connection Tcb notification channel unmark request. NcmContext = NcmContext, TCB State = State, PID = Pid, IsLoopback = IsLoopback, IsShutdown = IsShutdown, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NcmContext Pointer | |
State UInt32 | |
Pid UInt32 | |
IsLoopback UInt32 | |
IsShutdown UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1360: TCPIP: A packet has been cloned for a raw listener.
#Event ID 1361: TCPIP: A cloned packet has been dropped.
#Event ID 1362: IP: Interface = Interface IpAddress = IPAddress processing WolEvent = WoLEvent with Status = Status.
#Description
IP: Interface = Interface IpAddress = IPAddress processing WolEvent = WoLEvent with Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
IpAddrLength UInt32 | |
IPAddress Binary | |
WoLEvent UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1363: IP: Interface = Interface WolHandle = WolHandle has DestinationIpAddress = DestinationIPAddress TargetIpAddress1 = TargetIPAddress1 TargetIpAddress2 = TargetIPAddress2 Flags = Flags while processin...
#Description
IP: Interface = Interface WolHandle = WolHandle has DestinationIpAddress = DestinationIPAddress TargetIpAddress1 = TargetIPAddress1 TargetIpAddress2 = TargetIPAddress2 Flags = Flags while processing WolEvent = WoLEvent with Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
IpAddrLength UInt32 | |
WolHandle UInt32 | |
DestinationIPAddress Binary | |
TargetIPAddress1 Binary | |
TargetIPAddress2 Binary | |
Flags UInt32 | |
WoLEvent UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1364: TCP connection tuple inserted- TCB: Tcb LocalAddress: LocalAddress RemoteAddress: RemoteAddress.
#Event ID 1365: TCP connection tuple removed- TCB/TWTCB: Tcb LocalAddress: LocalAddress RemoteAddress: RemoteAddress.
#Event ID 1366: TCP port selection deferred for outbound connect- LocalAddress: LocalAddress.
#Description
TCP port selection deferred for outbound connect- LocalAddress: LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1367: Nbl Nbl OOB info (PathDirection): TcpIpChecksumNetBufferListInfo TcpIpChecksumNetBufferListInfo, TcpLargeSendNetBufferListInfo TcpLargeSendNetBufferListInfo, Ieee8021QNetBufferListInfo Ieee8021QNet...
#Description
Nbl Nbl OOB info (PathDirection): TcpIpChecksumNetBufferListInfo TcpIpChecksumNetBufferListInfo, TcpLargeSendNetBufferListInfo TcpLargeSendNetBufferListInfo, Ieee8021QNetBufferListInfo Ieee8021QNetBufferListInfo, NetBufferListHashValue NetBufferListHashValue, NetBufferListHashInfo NetBufferListHashInfo, VirtualSubnetInfo VirtualSubnetInfo, UdpSegmentationOffloadInfo/TcpRecvSegCoalesceInfo TcpRecvSegCoalesceInfo, NrtNameResolutionId/UdpRecvSegCoalesceOffloadInfo NrtNameResolutionInfo
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | |
PathDirection UInt32 | |
TcpIpChecksumNetBufferListInfo Pointer | |
TcpLargeSendNetBufferListInfo Pointer | |
Ieee8021QNetBufferListInfo Pointer | |
NetBufferListHashValue Pointer | |
NetBufferListHashInfo Pointer | |
VirtualSubnetInfo Pointer | |
TcpRecvSegCoalesceInfo Pointer | |
NrtNameResolutionInfo Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1367",
"version": "1",
"level": "17",
"task": "1367",
"opcode": "0",
"keywords": 9223372049739677696,
"time_created": "2026-03-16T00:21:34.388895400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A11CCA4F0",
"PathDirection": " 0",
"TcpIpChecksumNetBufferListInfo": "0x220015",
"TcpLargeSendNetBufferListInfo": "0x0",
"Ieee8021QNetBufferListInfo": "0x0",
"NetBufferListHashValue": "0xF92BBC40",
"NetBufferListHashInfo": "0x0",
"VirtualSubnetInfo": "0x0",
"TcpRecvSegCoalesceInfo": "0x0",
"NrtNameResolutionInfo": "0x0"
},
"message": ""
}
Event ID 1368: Teredo Add -- PID: PID started listening on LocalAddress.
#Description
Teredo Add -- PID: PID started listening on LocalAddress. AddressType AddressType. ScopeLevel ScopeLevel. Port Port. EndpointRecord EndpointRecord.
Message #
Fields #
| Name | Description |
|---|---|
PID UInt64 | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
AddressType UInt32 | |
ScopeLevel UInt32 | |
Port UInt32 | |
EndpointRecord Pointer |
Event ID 1369: Teredo Remove -- PID: PID stopped listening on LocalAddress.
#Description
Teredo Remove -- PID: PID stopped listening on LocalAddress. AddressType AddressType. ScopeLevel ScopeLevel. Port Port. EndpointRecord EndpointRecord.
Message #
Fields #
| Name | Description |
|---|---|
PID UInt64 | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
AddressType UInt32 | |
ScopeLevel UInt32 | |
Port UInt32 | |
EndpointRecord Pointer |
Event ID 1370: IP: RouteLookup - API: API DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintOveridden: ConstraintOverridden ReturnConstrained...
#Description
IP: RouteLookup - API: API DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintOveridden: ConstraintOverridden ReturnConstrained: ReturnConstrained OutgoingIfIndex: OutgoingInterfaceIndex NextHopAddr: NextHopAddress Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
API AnsiString | |
IpAddrLength UInt32 | |
DestinationAddress Binary | |
ConstrainSourceAddress Binary | |
ConstrainInterfaceIndex UInt32 | |
ConstrainForwardingTag UInt32 | |
ConstraintOverridden UInt32 | |
ReturnConstrained UInt32 | |
OutgoingInterfaceIndex UInt32 | |
NextHopAddress Binary | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1370",
"version": "0",
"level": "5",
"task": "1370",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-15T23:26:13.698249300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "1868",
"thread_id": "2740"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"API": "IppFindPath",
"IpAddrLength": " 16",
"DestinationAddress": "127.0.0.1",
"ConstrainSourceAddress": "0.0.0.0",
"ConstrainInterfaceIndex": " 0",
"ConstraintOverridden": " 0",
"ReturnConstrained": " 0",
"OutgoingInterfaceIndex": " 1",
"NextHopAddress": "127.0.0.1",
"Status": "0x0"
},
"message": ""
}
Event ID 1371: IP: SourceAddrLookup - DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex OutgoingIfIndex: OutgoingInterfaceIndex ReturnConstrained: Retu...
#Description
IP: SourceAddrLookup - DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex OutgoingIfIndex: OutgoingInterfaceIndex ReturnConstrained: ReturnConstrained SelectedSrcAddr: SelectedSourceAddress.
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | |
DestinationAddress Binary | |
ConstrainSourceAddress Binary | |
ConstrainInterfaceIndex UInt32 | |
OutgoingInterfaceIndex UInt32 | |
ReturnConstrained UInt32 | |
SelectedSourceAddress Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1371",
"version": "0",
"level": "5",
"task": "1371",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:21:40.067796000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IpAddrLength": " 16",
"DestinationAddress": "0.0.0.0",
"ConstrainSourceAddress": "0.0.0.0",
"ConstrainInterfaceIndex": " 0",
"OutgoingInterfaceIndex": " 6",
"ReturnConstrained": " 0",
"SelectedSourceAddress": "10.2.10.21"
},
"message": ""
}
Event ID 1372: WFP-ALE: Partition Count=PartitionCount Partition Mask=PartitionMask: Partition Id=%d Partition NumEntries = NumEntries.
#Event ID 1373: WFP-ALE: HotAdd/Remove: Old Partiton Count=OldPartitionCount Old Partition Mask=OldPartitionMask New Partiton Count=OldPartitionCount New Partition Mask=OldPartitionMask.
#Description
WFP-ALE: HotAdd/Remove: Old Partiton Count=OldPartitionCount Old Partition Mask=OldPartitionMask New Partiton Count=OldPartitionCount New Partition Mask=OldPartitionMask.
Message #
Fields #
| Name | Description |
|---|---|
OldPartitionCount UInt64 | |
OldPartitionMask UInt64 | |
NewPartitionCount UInt64 | |
NewPartitionMask UInt64 |
Event ID 1374: WFP-ALE: RemoteEndPoint Insertion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEnt...
#Description
WFP-ALE: RemoteEndPoint Insertion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | |
RemoteAddress Binary | |
RemotePort UInt64 | |
LocalAddress Binary | |
LocalPort UInt16 | |
PartitionId UInt64 | |
NumEntries UInt64 |
Event ID 1375: WFP-ALE: RemoteEndPoint Deletion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntr...
#Description
WFP-ALE: RemoteEndPoint Deletion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | |
RemoteAddress Binary | |
RemotePort UInt64 | |
LocalAddress Binary | |
LocalPort UInt16 | |
PartitionId UInt64 | |
NumEntries UInt64 |
Event ID 1376: WFP-ALE: ALE: low memory state detected.
#Event ID 1377: WFP-ALE: leaving low memory state.
#Description
WFP-ALE: leaving low memory state. HighMemoryEvent = HighMemoryEvent HighNonPagedPoolEvent = HighNonPagedPoolEvent.
Message #
Fields #
| Name | Description |
|---|---|
HighMemoryEvent UInt32 | |
HighNonPagedPoolEvent UInt32 | |
LowMemoryEvent UInt32 | |
LowNonPagedPoolEvent UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1377",
"version": "0",
"level": "4",
"task": "1373",
"opcode": "0",
"keywords": 9223372036854841344,
"time_created": "2026-03-15T23:26:23.462874700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"HighMemoryEvent": " 1",
"HighNonPagedPoolEvent": " 1",
"LowMemoryEvent": " 0",
"LowNonPagedPoolEvent": " 0"
},
"message": ""
}
Event ID 1378: WFP-ALE: Dpc for cleanup initiated: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.
#Event ID 1379: WFP: Dpc for cleanup QUEUED or RE-QUEUED: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.
#Description
WFP: Dpc for cleanup QUEUED or RE-QUEUED: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.
Message #
Fields #
| Name | Description |
|---|---|
HighMemoryEvent UInt32 | |
HighNonPagedPoolEvent UInt32 | |
LowMemoryEvent UInt32 | |
LowNonPagedPoolEvent UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1379",
"version": "0",
"level": "5",
"task": "1373",
"opcode": "0",
"keywords": 9223372036854841344,
"time_created": "2026-03-16T00:21:40.078370400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"HighMemoryEvent": " 1",
"HighNonPagedPoolEvent": " 1",
"LowMemoryEvent": " 0",
"LowNonPagedPoolEvent": " 0"
},
"message": ""
}
Event ID 1380: TCP: LEDBAT LedbatEvent: Connection Tcb, BaseDelayMs = BaseDelayMs, CurrentDelayMs = CurrentDelayMs, CWnd = Cwnd, SsThresh = SsThresh, SndWnd = SndWnd, DelayBasedCwndFactor DelayBasedCwndFactorPerc...
#Description
TCP: LEDBAT LedbatEvent: Connection Tcb, BaseDelayMs = BaseDelayMs, CurrentDelayMs = CurrentDelayMs, CWnd = Cwnd, SsThresh = SsThresh, SndWnd = SndWnd, DelayBasedCwndFactor DelayBasedCwndFactorPercent%, RemainingTimeMs = RemainingTimeMs.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
LedbatEvent UInt32 | |
Cwnd UInt32 | |
SsThresh UInt32 | |
SndWnd UInt32 | |
BaseDelayMs UInt16 | |
CurrentDelayMs UInt16 | |
RemainingTimeMs UInt32 | |
DelayBasedCwndFactorPercent Int32 |
Event ID 1381: TCP: AssociateNameResContext Endpoint: EndpointObj Status: %16 NameResolutionContext: IsConnectionObj DnsName: NameResContext InterfaceIndex: Status IPAddrCount: %5 IPAddrs: %7 %9 %11 %...
#Description
TCP: AssociateNameResContext Endpoint: EndpointObj Status: %16 NameResolutionContext: IsConnectionObj DnsName: NameResContext InterfaceIndex: Status IPAddrCount: %5 IPAddrs: %7 %9 %11 %13 %15.
Message #
Fields #
| Name | Description |
|---|---|
EndpointObj Pointer | |
IsConnectionObj UInt32 | |
NameResContext Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 1382: TCP: InspectConnectWithNameResContext Connection: Tcb (local: LocalAddress remote: RemoteAddress) NameResolutionContext: NameResContext DnsName: DnsName Status: Status.
#Description
TCP: InspectConnectWithNameResContext Connection: Tcb (local: LocalAddress remote: RemoteAddress) NameResolutionContext: NameResContext DnsName: DnsName Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Tcb Pointer | |
NameResContext Pointer | |
DnsName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1383: IP: Route [DestinationPrefix: PrDestinationPrefix/PrDestinationPrefixLength NextHop: PrNextHopAddress InterfaceIndex: PrInterfaceIndex InterfaceMetric: PrInterfaceMetric RouteMetric: PrRouteMetric]...
#Description
IP: Route [DestinationPrefix: PrDestinationPrefix/PrDestinationPrefixLength NextHop: PrNextHopAddress InterfaceIndex: PrInterfaceIndex InterfaceMetric: PrInterfaceMetric RouteMetric: PrRouteMetric] is preferred over Route [DestinationPrefix: NonPrDestinationPrefix/NonPrDestinationPrefixLength NextHop: NonPrNextHopAddress InterfaceIndex: NonPrInterfaceIndex InterfaceMetric: NonPrInterfaceMetric RouteMetric: NonPrRouteMetric] for Destination: DestinationAddress in Compartment: CompartmentId, Reason: PreferenceReason.
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | |
DestinationAddressLength UInt32 | |
DestinationAddress Binary | |
PrDestinationPrefixLength UInt32 | |
PrDestinationPrefixAddressLength UInt32 | |
PrDestinationPrefix Binary | |
PrNextHopAddressLength UInt32 | |
PrNextHopAddress Binary | |
PrInterfaceIndex UInt32 | |
PrInterfaceMetric UInt32 | |
PrRouteMetric UInt32 | |
NonPrDestinationPrefixLength UInt32 | |
NonPrDestinationPrefixAddressLength UInt32 | |
NonPrDestinationPrefix Binary | |
NonPrNextHopAddressLength UInt32 | |
NonPrNextHopAddress Binary | |
NonPrInterfaceIndex UInt32 | |
NonPrInterfaceMetric UInt32 | |
NonPrRouteMetric UInt32 | |
PreferenceReason UInt32 |
Event ID 1384: IP: Route [DestinationPrefix: DestinationPrefix/DestinationPrefixLength NextHop: NextHopAddress InterfaceIndex: InterfaceIndex RouteMetric: RouteMetric] is blocked for Destination: DestinationAddre...
#Description
IP: Route [DestinationPrefix: / NextHop: InterfaceIndex: RouteMetric: ] is blocked for Destination: ConstrainInterfaceIndex: ConstrainScopeZone: in Compartment: , Reason: .
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | |
DestinationAddressLength UInt32 | |
DestinationAddress Binary | |
DestinationPrefixLength UInt32 | |
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
InterfaceIndex UInt32 | |
RouteMetric UInt32 | |
ConstrainInterfaceIndex UInt32 | |
ConstrainScope UInt32 | |
BlockReason UInt32 |
Event ID 1385: TCP: Tail Loss Probe Send Connection = Tcb SndUna = SndUna, SndMax = SndMax, SendAvailable = SendAvailable, TailProbeSeq = TailProbeSeq, TailProbeLast = TailProbeLast, ControlsToSend = ControlsToSe...
#Description
TCP: Tail Loss Probe Send Connection = Tcb SndUna = SndUna, SndMax = SndMax, SendAvailable = SendAvailable, TailProbeSeq = TailProbeSeq, TailProbeLast = TailProbeLast, ControlsToSend = ControlsToSend, ThFlags = ThFlags.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 | |
SendAvailable UInt32 | |
TailProbeSeq UInt32 | |
TailProbeLast UInt32 | |
ControlsToSend UInt32 | |
ThFlags UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1385",
"version": "0",
"level": "4",
"task": "1380",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.721122900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"SndUna": "2308839694",
"SndMax": "2308842691",
"SendAvailable": " 2997",
"TailProbeSeq": "2308841231",
"TailProbeLast": "2308842691",
"ControlsToSend": " 0",
"ThFlags": "16"
},
"message": ""
}
Event ID 1386: TCP: Tail Loss Probe Event Connection = Tcb, Event = TlpEvent.
#Description
TCP: Tail Loss Probe Event Connection = Tcb, Event = TlpEvent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
TlpEvent UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1386",
"version": "0",
"level": "4",
"task": "1380",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388823900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TlpEvent": " 1"
},
"message": ""
}
Event ID 1387: TCP: RACK Event Connection = Tcb, Event = RackEvent, MinRTT = RackMinRtt, ReoWind = RackReoWind, TimeSlotDeltaMin = RackTimeSlotDeltaMin, SeqNum = SequenceNumber, Timestamp = Timestamp, RttSample =...
#Description
TCP: RACK Event Connection = Tcb, Event = RackEvent, MinRTT = RackMinRtt, ReoWind = RackReoWind, TimeSlotDeltaMin = RackTimeSlotDeltaMin, SeqNum = SequenceNumber, Timestamp = Timestamp, RttSample = RttSample.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
RackEvent UInt32 | |
RackMinRtt UInt32 | |
RackReoWind UInt32 | |
RackTimeSlotDeltaMin UInt32 | |
SequenceNumber UInt32 | |
Timestamp UInt32 | |
RttSample UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1387",
"version": "0",
"level": "4",
"task": "1381",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:14.411027300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f6654220-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "10828",
"thread_id": "9684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FF6654220",
"RackEvent": " 1",
"RackMinRtt": " 751",
"RackReoWind": " 0",
"RackTimeSlotDeltaMin": " 0",
"SequenceNumber": "2723729970",
"Timestamp": "4090263552",
"RttSample": " 751"
},
"message": ""
}
Event ID 1388: TCP: Fastopen state changed for connection = Tcb from OldState = OldState to NewState = NewState.
#Event ID 1389: UDP: endpoint (family=AddressFamily pid=ProcessId) create failed: address family not attached.
#Description
UDP: endpoint (family=AddressFamily pid=ProcessId) create failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1390: UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: compartment CompartmentId not found.
#Description
UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: compartment CompartmentId not found.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1391: UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) created.
#Description
UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) created.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1391",
"version": "1",
"level": "4",
"task": "1385",
"opcode": "0",
"keywords": 9223372036854776833,
"time_created": "2026-03-16T00:21:40.077667700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"Status": "0x0",
"ProcessId": " 228",
"CompartmentId": " 1",
"AddressFamily": " 23",
"ProcessStartKey": "2814749767106594"
},
"message": ""
}
Event ID 1392: UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: inspection status = Status.
#Description
UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: inspection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1393: UDP: endpoint Endpoint bind failed: address LocalAddress cannot be resolved, status = Status.
#Description
UDP: endpoint Endpoint bind failed: address LocalAddress cannot be resolved, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Endpoint Pointer |
Event ID 1394: UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: port-acquisition status = Status.
#Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: port-acquisition status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Endpoint Pointer |
Event ID 1395: UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: inspection status = Status.
#Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: inspection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Endpoint Pointer |
Event ID 1396: UDP: endpoint Endpoint (sockaddr=LocalAddress) bound.
#Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bound.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Endpoint Pointer | |
Pid UInt32 | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1396",
"version": "0",
"level": "4",
"task": "1390",
"opcode": "0",
"keywords": 9223372036854776841,
"time_created": "2026-03-16T00:21:40.078017600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::]:53893",
"Status": "0x0",
"Endpoint": "0xFFFF980A11735E80"
},
"message": ""
}
Event ID 1397: UDP: endpoint Endpoint (sockaddr=LocalAddress) closed.
#Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) closed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Endpoint Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1397",
"version": "0",
"level": "4",
"task": "1391",
"opcode": "0",
"keywords": 9223372105574253569,
"time_created": "2026-03-16T00:21:40.117474200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "2612"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::]:53893",
"Status": "0x0",
"Endpoint": "0xFFFF980A11735E80"
},
"message": ""
}
Event ID 1398: UDP: endpoint Endpoint closed.
#Description
UDP: endpoint Endpoint closed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Endpoint Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1398",
"version": "0",
"level": "4",
"task": "1392",
"opcode": "0",
"keywords": 9223372105574253569,
"time_created": "2026-03-16T00:21:40.118277500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11737aa0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "10580"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 0",
"LocalAddress": "",
"Status": "0x0",
"Endpoint": "0xFFFF980A11737AA0"
},
"message": ""
}
Event ID 1399: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address resolution status = Status.
#Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address resolution status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1400: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address validation failed.
#Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address validation failed.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1401: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: source-address selection status = Status.
#Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: source-address selection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1402: UDP: endpoint {Endpoint} too many packets queued for the pending join path.
#Event ID 1403: UDP: address family AddressFamilyadded to interface InterfaceIndex.
#Event ID 1404: UDP: address family AddressFamilyremoved from interface InterfaceIndex.
#Event ID 1405: UDP: Failure initializing transport protocol, status = Status.
#Description
UDP: Failure initializing transport protocol, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1406: UDP: Failure starting NLNPI client, status = Status.
#Description
UDP: Failure starting NLNPI client, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1407: UDP: Failure initializing NSI support, status = Status.
#Description
UDP: Failure initializing NSI support, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1408: UDP: Failure starting TLNPI provider, status = Status.
#Description
UDP: Failure starting TLNPI provider, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1409: UDP: Failure initializing QoS support, status = Status.
#Description
UDP: Failure initializing QoS support, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1410: UDP: Failure starting FailedQueueString, status = Status.
#Description
UDP: Failure starting FailedQueueString, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
FailedQueueString UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1411: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: could not allocate send context.
#Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: could not allocate send context.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1412: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path af failure, status = Status.
#Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path af failure, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1413: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path missing next hop failure.
#Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path missing next hop failure.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1414: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path next hop address failure.
#Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path next hop address failure.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1415: TCP: Early Retransmission, FACK or RACK, Connection = Tcb, SndUna = SndUna, SackIsLostSeq = SackIsLostSeq, DupAckCount = DupAckCount.
#Description
TCP: Early Retransmission, FACK or RACK, Connection = Tcb, SndUna = SndUna, SackIsLostSeq = SackIsLostSeq, DupAckCount = DupAckCount.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SackIsLostSeq UInt32 | |
DupAckCount UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1415",
"version": "0",
"level": "4",
"task": "1409",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:27:12.440656500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"SndUna": "4068749001",
"SackIsLostSeq": " 0",
"DupAckCount": " 1"
},
"message": ""
}
Event ID 1416: TCP: Ignoring fastopen SYN option due to limit on concurrent SYN_RCVD fastopen connections, Connection = Tcb, SynRcvdLimit = SynRcvdLimit.
#Event ID 1417: TCP: Failed to update fastopen key state, Location = Location, Status = Status.
#Description
TCP: Failed to update fastopen key state, Location = Location, Status = Status. Server-side fastopen will be disabled.
Message #
Fields #
| Name | Description |
|---|---|
Location UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1418: TCP: Fast Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
#Description
TCP: Fast Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
BytesToSend UInt32 | |
SndNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1418",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.489901200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"BytesToSend": " 1440",
"SndNxt": "155002622"
},
"message": ""
}
Event ID 1419: TCP: SACK Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
#Description
TCP: SACK Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
BytesToSend UInt32 | |
SndNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1419",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.490433800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"BytesToSend": " 38",
"SndNxt": "155004100"
},
"message": ""
}
Event ID 1420: TCP: Limited Transmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
#Description
TCP: Limited Transmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
BytesToSend UInt32 | |
SndNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1420",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:23:27.162052500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"BytesToSend": " 1440",
"SndNxt": "1228953133"
},
"message": ""
}
Event ID 1421: TCP: SACK Retransmit Additional Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
#Description
TCP: SACK Retransmit Additional Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
BytesToSend UInt32 | |
SndNxt UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1421",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:23:27.167320000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"BytesToSend": " 1440",
"SndNxt": "1228956013"
},
"message": ""
}
Event ID 1422: IPTransportProtocol: PathDirectionmessage.
#Description
IPTransportProtocol: PathDirectionmessage. Type = IcmpType, Code = IcmpCode, CompartmentId = CompartmentId, SourceAddress = SourceAddress, DestAddress = DestAddress.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | |
PathDirection UInt32 | |
IcmpType UInt32 | |
IcmpCode UInt32 | |
CompartmentId UInt32 | |
SourceAddressLength UInt32 | |
SourceAddress Binary | |
DestAddressLength UInt32 | |
DestAddress Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1422",
"version": "0",
"level": "4",
"task": "1413",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:40.180500700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 1",
"PathDirection": " 0",
"IcmpType": " 3",
"IcmpCode": " 3",
"CompartmentId": " 1",
"SourceAddressLength": " 16",
"SourceAddress": "10.2.10.21",
"DestAddressLength": " 16",
"DestAddress": "8.8.8.8"
},
"message": ""
}
Event ID 1423: IPTransportProtocol: PathDirectionpath drop.
#Description
IPTransportProtocol: PathDirectionpath drop. Type = IcmpType, Code = IcmpCode, Reason = DropReason, Status = Status, CompartmentId = CompartmentId, SourceAddress = SourceAddress, DestAddress = DestAddress.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | |
PathDirection UInt32 | |
IcmpType UInt32 | |
IcmpCode UInt32 | |
DropReason UInt32 | |
Status UInt32 | NTSTATUS reference |
CompartmentId UInt32 | |
SourceAddressLength UInt32 | |
SourceAddress Binary | |
DestAddressLength UInt32 | |
DestAddress Binary | |
IfIndex UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1423",
"version": "1",
"level": "4",
"task": "1414",
"opcode": "0",
"keywords": 9223373136366403712,
"time_created": "2026-03-15T23:30:50.067428800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "10828",
"thread_id": "12980"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 1",
"PathDirection": " 0",
"IcmpType": " 3",
"IcmpCode": " 3",
"DropReason": " 12",
"Status": "0xC000021B",
"CompartmentId": " 1",
"SourceAddressLength": " 16",
"SourceAddress": "10.2.10.11",
"DestAddressLength": " 16",
"DestAddress": "10.2.10.21",
"IfIndex": " 4"
},
"message": ""
}
Event ID 1424: IPTransportProtocol: Echo timeout.
#Description
IPTransportProtocol: Echo timeout. Status = IcmpCode.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | |
PathDirection UInt32 | |
IcmpType UInt32 | |
IcmpCode UInt32 | |
DropReason UInt32 | |
Status UInt32 | NTSTATUS reference |
CompartmentId UInt32 | |
SourceAddressLength UInt32 | |
SourceAddress Binary | |
DestAddressLength UInt32 | |
DestAddress Binary |
Event ID 1425: Component Timer state changed to CurrentState by Processor Processor Usage = ProcessorUsage at Tick = CurrentTick.
#Event ID 1426: TCP: connection Tcb send complete NumBytes bytes at SndNxt (Injected).
#Description
TCP: connection Tcb send complete NumBytes bytes at SndNxt (Injected).
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Injected UnicodeString | |
NumBytes UInt32 | |
SndNxt UInt32 | |
ActivityID Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1426",
"version": "0",
"level": "5",
"task": "1417",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390792600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "normal",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1427: IP: Compartment creation.
#Description
IP: Compartment creation. Compartment = CompartmentId, Protocol = AddressFamily, Private = Private, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | |
AddressFamily UInt32 | |
Private UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1428: IP: Compartment deletion.
#Description
IP: Compartment deletion. Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | |
AddressFamily UInt32 | |
Private UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1429: TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd = SndWnd, InRecovery = InRecovery, TimeSinceLastLossMS = TimeSinceLastLossMS, CubicCwnd...
#Description
TCP: connection : Cumulative Ack event, SeqNo = , BytesAcked = , CWnd = , SndWnd = , InRecovery = , TimeSinceLastLossMS = , CubicCwnd = , AimdCwnd = , K = , Wmax = , LastWmax = , MaxSndWnd = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SndWnd UInt32 | |
BytesAcked UInt32 | |
SeqNo UInt32 | |
InRecovery UInt8 | |
TimeSinceLastLossMS UInt64 | |
CubicCwnd UInt64 | |
AimdCwnd UInt32 | |
K UInt64 | |
Wmax UInt32 | |
LastWmax UInt32 | |
MaxSndWnd UInt32 | |
IsLimitedSlowStart UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1429",
"version": "1",
"level": "4",
"task": "1420",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:36.015001500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{10708010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A10708010",
"Cwnd": " 27376",
"SndWnd": " 262656",
"BytesAcked": " 0",
"SeqNo": "3807647817",
"InRecovery": "0",
"TimeSinceLastLossMS": "0",
"CubicCwnd": "0",
"AimdCwnd": " 0",
"K": "0",
"Wmax": " 0",
"LastWmax": " 0",
"MaxSndWnd": " 262656",
"IsLimitedSlowStart": "0"
},
"message": ""
}
Event ID 1430: TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo CwrMax = CwrMax.
#Description
TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo CwrMax = CwrMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SSThresh UInt32 | |
DupAckCount UInt32 | |
SeqNo UInt32 | |
CwrMax UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1430",
"version": "0",
"level": "4",
"task": "1421",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-15T23:27:12.440654900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"Cwnd": " 22020",
"SSThresh": " 16760",
"DupAckCount": " 1",
"SeqNo": "4068749001",
"CwrMax": "4068749000"
},
"message": ""
}
Event ID 1431: IP: Compartment cleanup.
#Description
IP: Compartment cleanup. Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | |
AddressFamily UInt32 | |
Private UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1432: IP: Interface network category state change.
#Description
IP: Interface network category state change. Interface = IfIndex, Compartment = CompartmentId , Protocol = AddressFamily, NetworkCategory = NetworkCategory, DomainNetworkLocation = DomainNetworkLocation, DomainType = DomainType, Signature = NetworkSignature.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
NetworkCategory UInt32 | |
DomainNetworkLocation UInt32 | |
DomainType UInt32 | |
NetworkSignature GUID |
Event ID 1433: IP: Interface creation.
#Description
IP: Interface creation. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, PhysicalMediumType = PhysicalMediumType, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
PhysicalMediumType UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1434: IP: Interface deletion.
#Description
IP: Interface deletion. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
PhysicalMediumType UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1435: IP: Interface cleanup.
#Description
IP: Interface cleanup. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
PhysicalMediumType UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1436: IP: SubInterface creation.
#Description
IP: SubInterface creation. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
SubIfIndex UInt32 | |
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1437: IP: SubInterface deletion.
#Description
IP: SubInterface deletion. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
SubIfIndex UInt32 | |
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1438: IP: SubInterface cleanup.
#Description
IP: SubInterface cleanup. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
SubIfIndex UInt32 | |
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1439: IP: Interface change Notification.
#Event ID 1440: IP: Interface internet connectivity status change.
#Description
IP: Interface internet connectivity status change. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, OldConnectivityStatus = OldConnectivityStatus, NewConnectivityStatus = NewConnectivityStatus.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
OldConnectivityStatus UInt32 | |
NewConnectivityStatus UInt32 |
Event ID 1441: IP: Address change notification.
#Description
IP: Address change notification. Address = SourceAddress, Interface = IfIndex, Compartment = CompartmentId, Protocol = Protocol, Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddressLength UInt32 | |
SourceAddress Binary | |
IfIndex UInt32 | |
CompartmentId UInt32 | |
Protocol AnsiString | Known values
|
Reason UInt32 | |
State UInt32 | |
NotificationType UInt32 | |
DadState UInt32 |
Event ID 1442: IP: Route change notification.
#Description
IP: Route change notification. DestinationPrefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Interface = IfIndex, Compartment = CompartmentId, NotifyFlags = NotifyFlags.
Message #
Fields #
| Name | Description |
|---|---|
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
DestinationPrefixLength UInt32 | |
CompartmentId UInt32 | |
IfIndex UInt32 | |
NotifyFlags UInt64 | |
State UInt32 | |
NotificationType UInt32 |
Event ID 1443: IP: Neighbor change notification.
#Description
IP: Neighbor change notification. IpAddress = IPAddress, DlAddress = DLAddress, Interface = IfIndex, Compartment = CompartmentId, State = NeighborState, Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | |
IPAddress Binary | |
DlAddrLength UInt32 | |
DLAddress Binary | |
IfIndex UInt32 | |
CompartmentId UInt32 | |
NeighborState UInt32 | |
Reason UInt32 | |
NotificationState UInt32 | |
NotificationType UInt32 |
Event ID 1444: IP: Address DAD state change.
#Description
IP: Address DAD state change. Address = SourceAddress, Interface = IfIndex, Compartment = CompartmentId, OldState = OldDadState, NewState = NewDadState, Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddressLength UInt32 | |
SourceAddress Binary | |
IfIndex UInt32 | |
CompartmentId UInt32 | |
OldDadState UInt32 | |
NewDadState UInt32 | |
Reason UInt32 |
Event ID 1445: IP: Route Dead Gateway Detection state change.
#Description
IP: Route Dead Gateway Detection state change. DestinationPrefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Interface = IfIndex, Compartment = CompartmentId, OldState = OldState, NewState = NewState, OldProbeCount = OldProbeCount, NewProbeCount = NewProbeCount, OldUnreachablePaths = OldUnreachablePaths, NewUnreachablePaths = NewUnreachablePaths, OldMovedPaths = OldMovedPaths, NewMovedPaths = NewMovedPaths, TotalPaths = TotalPaths, OldStateChangeTick = OldStateChangeTick, NewStateChangeTick = NewStateChangeTick, DgdNeedsReset = DgdNeedsReset, Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
DestinationPrefixLength UInt32 | |
CompartmentId UInt32 | |
IfIndex UInt32 | |
OldState UInt32 | |
NewState UInt32 | |
OldProbeCount UInt32 | |
NewProbeCount UInt32 | |
OldUnreachablePaths UInt32 | |
NewUnreachablePaths UInt32 | |
OldMovedPaths UInt32 | |
NewMovedPaths UInt32 | |
TotalPaths UInt32 | |
OldStateChangeTick UInt32 | |
NewStateChangeTick UInt32 | |
DgdNeedsReset UInt32 | |
Reason UInt32 |
Event ID 1446: IP: Disconnecting TCP connections with Address = Address, Interface = IfIndex, Compartment = CompartmentId, SkipLocal = SkipLocal, SkipOnLink = SkipOnLink.
#Event ID 1447: TCP: connection Tcb: Sending paced chunk of QuantizedAllowance bytes with CWnd = Cwnd, SndWnd = SndWnd, BytesAvailable = BytesAvailable, BytesOutstanding = BytesOutstanding.
#Description
TCP: connection Tcb: Sending paced chunk of QuantizedAllowance bytes with CWnd = Cwnd, SndWnd = SndWnd, BytesAvailable = BytesAvailable, BytesOutstanding = BytesOutstanding.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Cwnd UInt32 | |
SndWnd UInt32 | |
BytesAvailable UInt32 | |
BytesOutstanding UInt32 | |
QuantizedAllowance UInt32 | |
Allowance UInt32 | |
OriginalBytesToSend UInt32 |
Event ID 1448: Fallback: Context = Fallback, Feature = Feature, TraceReason = Reason, Confidence = Confidence, Successes = Successes, Failures = Failures.
#Event ID 1449: TCPIP: TCB Tcb using fast loopback.
#Event ID 1450: IP: Router information change notification.
#Event ID 1451: IP: Event.
#Description
IP: Event. Interface = Interface, Compartment = CompartmentId, RouterAddress = RouterAddress, DNS Server/Suffix: DNSServerAddress DNSSuffix, Lifetime = Lifetime.
Message #
Fields #
| Name | Description |
|---|---|
Event UInt32 | |
Interface UInt32 | |
CompartmentId UInt32 | |
RouterAddrLength UInt32 | |
RouterAddress Binary | |
DnsAddrLength UInt32 | |
DNSServerAddress Binary | |
DNSSuffix AnsiString | |
Lifetime UInt32 |
Event ID 1452: IP: Route rundown.
#Description
IP: Route rundown. Interface = Interface, Compartment = Compartment, Prefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Metric = Metric, State = State, Origin = Origin, Age = Age, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Flags = Flags.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Compartment UInt32 | |
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
DestinationPrefixLength UInt32 | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
Metric UInt32 | |
State UInt32 | |
Origin UInt32 | |
Age UInt64 | |
ValidLifetime UInt64 | |
PreferredLifetime UInt64 | |
Flags UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1452",
"version": "0",
"level": "4",
"task": "1443",
"opcode": "0",
"keywords": 9223372586610589856,
"time_created": "2026-03-16T00:21:34.295267700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Interface": " 6",
"Compartment": " 1",
"DestinationPrefixAddressLength": " 16",
"DestinationPrefix": "0.0.0.0",
"DestinationPrefixLength": " 0",
"NextHopAddressLength": " 16",
"NextHopAddress": "10.2.10.254",
"Metric": " 256",
"State": " 0",
"Origin": " 0",
"Age": "0x1A11",
"ValidLifetime": "0xFFFFFFFF",
"PreferredLifetime": "0xFFFFFFFF",
"Flags": "0x388"
},
"message": ""
}
Event ID 1453: TCP: CUBIC ECN event.
#Event ID 1454: INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectAction, Status = Status.
#Description
INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectAction, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Owner Pointer | |
InspectHandle Pointer | |
InspectType UInt32 | |
InspectAction UInt32 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1454",
"version": "0",
"level": "4",
"task": "1445",
"opcode": "0",
"keywords": 9223372036854775936,
"time_created": "2026-03-16T00:21:34.388718700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Owner": "0xFFFF980A1018B560",
"InspectHandle": "0xFFFF980A17030CE0",
"InspectType": " 0",
"InspectAction": " 1",
"Status": "0x0"
},
"message": ""
}
Event ID 1455: INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectPort, Status = Status.
#Description
INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectPort, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Owner Pointer | |
InspectHandle Pointer | |
InspectType UInt32 | |
InspectPort UInt32 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1455",
"version": "0",
"level": "4",
"task": "1445",
"opcode": "0",
"keywords": 9223372036854775936,
"time_created": "2026-03-16T00:21:40.077855500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0b1c4090-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Owner": "0xFFFF980A0B1C4090",
"InspectHandle": "0xFFFF980A13FE6CC0",
"InspectType": " 17",
"InspectPort": " 0",
"Status": "0x0"
},
"message": ""
}
Event ID 1456: FallbackCheck: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
#Description
FallbackCheck: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | |
Feature UInt32 | |
Failed UInt32 | |
Succeeded UInt32 | |
InProbe UInt32 | |
PathsProbed UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1457: FallbackUpdate: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
#Description
FallbackUpdate: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | |
Feature UInt32 | |
Failed UInt32 | |
Succeeded UInt32 | |
InProbe UInt32 | |
PathsProbed UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1458: Fallback: Permanently disabling feature, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
#Description
Fallback: Permanently disabling feature, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | |
Feature UInt32 | |
Failed UInt32 | |
Succeeded UInt32 | |
InProbe UInt32 | |
PathsProbed UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1459: Fallback: Enabling feature for this boot session, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
#Description
Fallback: Enabling feature for this boot session, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | |
Feature UInt32 | |
Failed UInt32 | |
Succeeded UInt32 | |
InProbe UInt32 | |
PathsProbed UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1460: Fallback: Feature previously disabled, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
#Description
Fallback: Feature previously disabled, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | |
Feature UInt32 | |
Failed UInt32 | |
Succeeded UInt32 | |
InProbe UInt32 | |
PathsProbed UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1461: TCP Fastopen fallback update: Tcb = Tcb, FastopenState = FastopenState, DataBytesIn = DataBytesIn, ShutdownStatus = ShutdownStatus, ProbeStatus = ProbeStatus.
#Event ID 1462: Disabling feature until connectivity is established: CompartmentId =CompartmentId, IfIndex = IfIndex, Feature = Feature, ConnectivityStatus = ConnectivityStatus.
#Event ID 1463: Disabling Feature for loopback connection.
#Event ID 1464: Disabling TCP Fastopen for BaseEndpoint = BaseEndpoint because an incompatible WFP callout is installed.
#Event ID 1465: IP: Setting source constraint for route lookup - Compartment: Compartment DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintFl...
#Description
IP: Setting source constraint for route lookup - Compartment: Compartment DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintFlags: ConstraintFlags.
Message #
Fields #
| Name | Description |
|---|---|
Compartment UInt32 | |
DestinationAddrLength UInt32 | |
DestinationAddress Binary | |
ConstrainSourceAddrLength UInt32 | |
ConstrainSourceAddress Binary | |
ConstrainInterfaceIndex UInt32 | |
ConstraintFlags UInt32 | |
TransportProtocol UInt32 | |
IcmpType UInt8 | |
IcmpCode UInt8 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1465",
"version": "0",
"level": "5",
"task": "1450",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:21:38.719138100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Compartment": " 1",
"DestinationAddrLength": " 16",
"DestinationAddress": "10.2.10.11",
"ConstrainSourceAddrLength": " 16",
"ConstrainSourceAddress": "10.2.10.21",
"ConstrainInterfaceIndex": " 6",
"ConstraintFlags": "0x1"
},
"message": ""
}
Event ID 1466: WFP-ALE: RemoteEndPoint Insertion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
#Description
WFP-ALE: RemoteEndPoint Insertion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddress Binary | |
PartitionId UInt64 | |
NumEntries UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1466",
"version": "0",
"level": "4",
"task": "1372",
"opcode": "0",
"keywords": 9223372036854808576,
"time_created": "2026-03-16T00:21:40.078425500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressLength": " 16",
"LocalAddress": "10.2.10.21:53893",
"RemoteAddress": "10.2.10.11:53",
"PartitionId": "4",
"NumEntries": "4"
},
"message": ""
}
Event ID 1467: WFP-ALE: RemoteEndPoint Deletion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
#Description
WFP-ALE: RemoteEndPoint Deletion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddress Binary | |
PartitionId UInt64 | |
NumEntries UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1467",
"version": "0",
"level": "4",
"task": "1372",
"opcode": "0",
"keywords": 9223372036854808576,
"time_created": "2026-03-16T00:21:40.078776800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressLength": " 16",
"LocalAddress": "10.2.10.21",
"RemoteAddress": "8.8.8.8:1",
"PartitionId": "4",
"NumEntries": "3"
},
"message": ""
}
Event ID 1468: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) system abort.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) system abort. PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 | |
Reason UInt32 |
Event ID 1469: Disabling Feature due to no next hop.
#Event ID 1470: TCP: endpoint (sockaddr=LocalAddressLength) bind failed: wake status = LocalAddress.
#Description
TCP: endpoint (sockaddr=LocalAddressLength) bind failed: wake status = LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Event ID 1471: UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: wake status = Status.
#Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: wake status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
Endpoint Pointer |
Event ID 1472: Acquire wake port Port, type=AcquireType, family=AddressFamily, IF=Interface, compartment=Compartment.
#Event ID 1473: TCP: Connection Tcb reached max SACK queue length.
#Event ID 1474: TCP: Connection Tcb requested fast open.
#Event ID 1475: TCP: CUBIC Hystart state change event.
#Description
TCP: CUBIC Hystart state change event. Connection Tcb, State State, CWnd Cwnd, SSThresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
State UInt16 | |
Cwnd UInt32 | |
SSThresh UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1475",
"version": "0",
"level": "4",
"task": "1463",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.489856100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"State": "2",
"Cwnd": " 16734",
"SSThresh": "4294967295"
},
"message": ""
}
Event ID 1476: IP: Transmitting loopback Nbl Nbl.
#Description
IP: Transmitting loopback Nbl Nbl. Interface=Interface, Compartment=Compartment, Src=SourceAddress, Dst=DestinationAddress, Proto=IPTransportProtocol.
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | |
Interface UInt32 | |
Compartment UInt32 | |
AddressLength UInt32 | |
DestinationAddress Binary | |
SourceAddress Binary | |
IPTransportProtocol UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1476",
"version": "0",
"level": "17",
"task": "1464",
"opcode": "0",
"keywords": 9223372036858970112,
"time_created": "2026-03-16T00:23:11.240868900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "11564"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A1A0CE070",
"Interface": " 6",
"Compartment": " 1",
"AddressLength": " 16",
"DestinationAddress": "224.0.0.251:5353",
"SourceAddress": "10.2.10.21:5353",
"IPTransportProtocol": " 17"
},
"message": ""
}
Event ID 1477: TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa...
#Description
TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa \ NonRecovDa NonRecovDaEpisodes NonRecovDaEpisodes DupAcksIn DupAcksIn BytesRetrans BytesRetrans Timeouts Timeouts SpuriousRtoDetections SpuriousRtoDetections FastRetran FastRetran MaxSsthresh MaxSsthresh MaxSsCwnd MaxSsCwnd \ MaxCaCwnd MaxCaCwnd SndLimTransRwin SndLimTransRwin SndLimTimeRwin SndLimTimeRwin SndLimBytesRwin SndLimBytesRwin SndLimTransCwnd SndLimTransCwnd SndLimTimeCwnd SndLimTimeCwnd SndLimBytesCwnd SndLimBytesCwnd \ SndLimTransSnd SndLimTransSnd SndLimTimeSnd SndLimTimeRSnd SndLimBytesSnd SndLimBytesRSnd ConnectionTimeMs ConnectionTimeMs Timestamps TimestampsEnabled RttUs RttUs MinRtt MinRttUs MaxRtt MaxRttUs SynRetrans SynRetrans CongestionAlgorithm CongestionAlgorithm \ State State Local LocalAddress Remote RemoteAddress CWnd CWnd SsThresh SsThresh RcvWnd RcvWnd RcvBuf RcvBuf SndWnd SndWnd \ InterfaceIndex InterfaceIndex LocalPort LocalPort IsLoopback IsLoopback.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
DataBytesOut UInt64 | |
DataBytesIn UInt64 | |
DataSegmentsOut UInt64 | |
DataSegmentsIn UInt64 | |
SegmentsOut UInt64 | |
SegmentsIn UInt64 | |
NonRecovDa UInt32 | |
NonRecovDaEpisodes UInt32 | |
DupAcksIn UInt32 | |
BytesRetrans UInt32 | |
Timeouts UInt32 | |
SpuriousRtoDetections UInt32 | |
FastRetran UInt32 | |
MaxSsthresh UInt32 | |
MaxSsCwnd UInt32 | |
MaxCaCwnd UInt32 | |
SndLimTransRwin UInt32 | |
SndLimTimeRwin UInt32 | |
SndLimBytesRwin UInt64 | |
SndLimTransCwnd UInt32 | |
SndLimTimeCwnd UInt32 | |
SndLimBytesCwnd UInt64 | |
SndLimTransSnd UInt32 | |
SndLimTimeRSnd UInt32 | |
SndLimBytesRSnd UInt64 | |
ConnectionTimeMs UInt64 | |
TimestampsEnabled UInt32 | |
RttUs UInt32 | |
MinRttUs UInt32 | |
MaxRttUs UInt32 | |
SynRetrans UInt32 | |
CongestionAlgorithm UInt32 | |
State UInt32 | |
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
CWnd UInt32 | |
SsThresh UInt32 | |
RcvWnd UInt32 | |
RcvBuf UInt32 | |
SndWnd UInt32 | |
InterfaceIndex UInt32 | |
LocalPort UInt32 | |
IsLoopback Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1477",
"version": "1",
"level": "16",
"task": "1341",
"opcode": "0",
"keywords": 9223407221226864640,
"time_created": "2026-03-16T00:21:38.733329900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"DataBytesOut": "426",
"DataBytesIn": "5091",
"DataSegmentsOut": "2",
"DataSegmentsIn": "5",
"SegmentsOut": "6",
"SegmentsIn": "8",
"NonRecovDa": " 0",
"NonRecovDaEpisodes": " 0",
"DupAcksIn": " 0",
"BytesRetrans": " 0",
"Timeouts": " 0",
"SpuriousRtoDetections": " 0",
"FastRetran": " 0",
"MaxSsthresh": "4294967295",
"MaxSsCwnd": " 15027",
"MaxCaCwnd": " 0",
"SndLimTransRwin": " 0",
"SndLimTimeRwin": " 0",
"SndLimBytesRwin": "0",
"SndLimTransCwnd": " 0",
"SndLimTimeCwnd": " 0",
"SndLimBytesCwnd": "0",
"SndLimTransSnd": " 1",
"SndLimTimeRSnd": " 0",
"SndLimBytesRSnd": "430",
"ConnectionTimeMs": "14",
"TimestampsEnabled": " 0",
"RttUs": " 1146",
"MinRttUs": " 982",
"MaxRttUs": " 1717",
"SynRetrans": " 0",
"CongestionAlgorithm": " 5",
"State": " 0",
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"CWnd": " 15027",
"SsThresh": "4294967295",
"RcvWnd": " 2098020",
"RcvBuf": " 2098020",
"SndWnd": " 262144",
"InterfaceIndex": " 6",
"LocalPort": " 24855",
"IsLoopback": "false"
},
"message": ""
}
Event ID 1478: TCPIP: Framing layer PathDirection (AddressFamily=AddressFamily) dropped PacketCount packet(s) on interface=Interface, Reason=Reason, Data=Data.
#Event ID 1479: TCP: Connection Tcb Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) sent RST with Local = LocalSockAddr, Remote = RemoteSockAddr.
#Description
TCP: Connection Tcb Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) sent RST with Local = LocalSockAddr, Remote = RemoteSockAddr. Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
IPTransportProtocol UInt32 | |
AddressFamily UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary | |
Reason UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1479",
"version": "0",
"level": "4",
"task": "1466",
"opcode": "0",
"keywords": 9223372586610589824,
"time_created": "2026-03-16T00:22:37.889812500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"LocalSockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:52990",
"RemoteSockAddrLength": " 16",
"RemoteSockAddr": "52.159.108.190:443",
"Reason": " 10"
},
"message": ""
}
Event ID 1480: TCP connection failed with Status = Status, Local = LocalSockAddr, Remote = RemoteSockAddr, ProcessId = TcpState, TcpState = ProcessId at Hour:Minute:Second Reason = Reason.
#Description
TCP connection failed with Status = Status, Local = LocalSockAddr, Remote = RemoteSockAddr, ProcessId = TcpState, TcpState = ProcessId at Hour:Minute:Second Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary | |
TcpState UInt32 | |
ProcessId UInt32 | |
Hour UInt16 | |
Minute UInt16 | |
Second UInt16 | |
Reason UInt32 | |
ProcessStartKey UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1480",
"version": "1",
"level": "16",
"task": "1467",
"opcode": "0",
"keywords": 9223407221226864640,
"time_created": "2026-03-16T00:21:34.294926800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Status": "0xC0000241",
"LocalSockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:50542",
"RemoteSockAddrLength": " 16",
"RemoteSockAddr": "20.42.65.85:443",
"TcpState": " 6",
"ProcessId": " 3688",
"Hour": "0",
"Minute": "17",
"Second": "1",
"Reason": " 14",
"ProcessStartKey": "2814749767106643"
},
"message": ""
}
Event ID 1481: TCP: Connection Tcb PRR send SackIsLostSeq SackIsLostSeq SackInFlight SackInFlight SackBytes SackBytes SackIsLost SackIsLost SsThresh SsThresh RecoveryFS HeadSeq AckedData AckedData BytesInFlight B...
#Description
TCP: Connection Tcb PRR send SackIsLostSeq SackIsLostSeq SackInFlight SackInFlight SackBytes SackBytes SackIsLost SackIsLost SsThresh SsThresh RecoveryFS HeadSeq AckedData AckedData BytesInFlight BytesInFlight BytesToSend BytesToSend PrrDelivered PrrDelivered PrrOut PrrOut.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SackIsLostSeq UInt32 | |
SackInFlight UInt32 | |
SackBytes UInt32 | |
SackIsLost UInt32 | |
SsThresh UInt32 | |
HeadSeq UInt32 | |
AckedData UInt32 | |
BytesInFlight UInt32 | |
BytesToSend Int64 | |
PrrDelivered UInt32 | |
PrrOut UInt32 |
Event ID 1482: UDP: Endpoint Endpoint segment message.
#Description
UDP: Endpoint Endpoint segment message. SegmentSize = SegmentSize (0 == No Segmentation) MessageLength = MessageLength HwDatagrams = HwDatagrams HwSegments = HwSegments SwSegments = SwSegments Status = SubMssSegments.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
SegmentSize UInt32 | |
MessageLength UInt64 | |
HwDatagrams UInt32 | |
HwSegments UInt32 | |
SwSegments UInt32 | |
SubMssSegments UInt32 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1482",
"version": "1",
"level": "5",
"task": "1469",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.078220100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"SegmentSize": " 0",
"MessageLength": "63",
"HwDatagrams": " 0",
"HwSegments": " 0",
"SwSegments": " 0",
"SubMssSegments": " 0",
"Status": "0x0"
},
"message": ""
}
Event ID 1483: UDP: Endpoint Endpoint segmentation offload unavailable.
#Description
UDP: Endpoint Endpoint segmentation offload unavailable. Reason = FailureReason SegmentSize = SegmentSize LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
FailureReason UInt32 | Known values
|
SegmentSize UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary |
Event ID 1484: TCPIP: Framing layer interface IfIndex (AddressFamily = AddressFamily) failed to bind to its provider.
#Description
TCPIP: Framing layer interface IfIndex (AddressFamily = AddressFamily) failed to bind to its provider. Code = FailureCode. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
AddressFamily UInt32 | |
FailureCode UInt32 | NTSTATUS reference |
Status UInt32 | NTSTATUS reference |
Event ID 1485: TCPIP: OID request from framing layer interface IfIndex (AddressFamily = AddressFamily) failed.
#Description
TCPIP: OID request from framing layer interface IfIndex (AddressFamily = AddressFamily) failed. OID = OID. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
AddressFamily UInt32 | |
OID UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1486: TCPIP received a status indication on interface IfIndex.
#Event ID 1487: IP: Failed to set socket option.
#Description
IP: Failed to set socket option. Level = SocketOptionLevel. Option = SocketOptionValue. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
SocketOptionLevel UInt32 | |
SocketOptionValue UInt32 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1487",
"version": "0",
"level": "2",
"task": "1474",
"opcode": "0",
"keywords": 9223372036854775952,
"time_created": "2026-03-16T00:23:11.242873300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "2612"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"SocketOptionLevel": " 41",
"SocketOptionValue": " 9",
"Status": "0xC0000225"
},
"message": ""
}
Event ID 1488: IP: Failed to set socket IOCTL.
#Description
IP: Failed to set socket IOCTL. IOCTL = SocketIoctl. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
SocketIoctl UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1489: Failed to process multicast RequestType request.
#Description
Failed to process multicast RequestType request. Address = IPv4Address IPv6Address. Source Address = IPv4SourceAddress IPv6SourceAddress. Reason = FailureReason. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
RequestType UInt32 | |
IPv4Address UInt32 | |
IPv4SourceAddress UInt32 | |
IpAddrLength UInt32 | |
IpSourceAddrLength UInt32 | |
IPv6Address Binary | |
IPv6SourceAddress Binary | |
FailureReason UInt32 | Known values
|
Status UInt32 | NTSTATUS reference |
Event ID 1490: Processed multicast RequestType request successfully.
#Description
Processed multicast RequestType request successfully. Address = IPv4Address IPv6Address. Source Address = IPv4SourceAddress IPv6SourceAddress.
Message #
Fields #
| Name | Description |
|---|---|
RequestType UInt32 | |
IPv4Address UInt32 | |
IPv4SourceAddress UInt32 | |
IpAddrLength UInt32 | |
IpSourceAddrLength UInt32 | |
IPv6Address Binary | |
IPv6SourceAddress Binary |
Event ID 1491: MessageType.
#Event ID 1492: MessageType.
#Description
MessageType. Interface = IfIndex. Address = IPv4Address IPv6Address. Data = Data. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
MessageType UInt32 | |
IfIndex UInt32 | |
IPv4Address UInt32 | |
IpAddrLength UInt32 | |
IPv6Address Binary | |
Data UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1493: Invalid ECN codepoints in reassembly.
#Event ID 1494: Reassembly failure: packets do not add up correctly.
#Event ID 1495: Reassembly failure: failed to restore IPSec packet history.
#Description
Reassembly failure: failed to restore IPSec packet history. Interface = IfIndex. Address family = AddressFamily. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
AddressFamily UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1496: Could not transfer FragmentContextDirection.
#Event ID 1497: Attempting to GroupChangeType the multicast group at FL.
#Description
Attempting to GroupChangeType the multicast group at FL. Interface = IfIndex. Address = IPv4Address IPv6Address. Data = Data. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
GroupChangeType UInt32 | |
IfIndex UInt32 | |
IPv4Address UInt32 | |
IpAddrLength UInt32 | |
IPv6Address Binary | |
Data UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1498: Failed to update address list at FL.
#Description
Failed to update address list at FL. Interface = IfIndex. Address Family = AddressFamily. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
AddressFamily UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1499: Too many DAD failures, so will not create temporary address.
#Event ID 1500: Failed to address interface; deleting it.
#Description
Failed to address interface; deleting it. Interface = IfIndex. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1501: Failed to reach default gateway after reconnect; cleaning settings.
#Event ID 1502: Failed to sync interface with registry.
#Description
Failed to sync interface with registry. Interface = IfIndex. Field = Field. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
Field UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 1503: Failed to Release an active reference on the interface.
#Description
Failed to Release an active reference on the interface. Interface = IfIndex. Reference Reason = Subtask. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Release UInt32 | |
IfIndex UInt32 | |
Subtask UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1504: Redirect path hijack for destination IPv4DestinationAddress IPv4NextHop from IPv6DestinationAddress IPv6NextHop.
#Description
Redirect path hijack for destination IPv4DestinationAddress IPv4NextHop from IPv6DestinationAddress IPv6NextHop. Interface = IfIndex.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
IPv4DestinationAddress UInt32 | |
IPv4NextHop UInt32 | |
IpAddrLength UInt32 | |
IPv6DestinationAddress Binary | |
IPv6NextHop Binary |
Event ID 1505: Redirect path rate limit for IPv6 source address IPv6Address.
#Event ID 1506: Dropped AddressFamily fragment.
#Event ID 1507: Reassembly timeout.
#Description
Reassembly timeout. Interface = IfIndex. Id = ReassemblyId. Source Address = IPv4SourceAddress IPv6SourceAddress. Destination Address = IPv4DestinationAddress IPv6DestinationAddress.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
ReassemblyId UInt32 | |
IPv4SourceAddress UInt32 | |
IPv4DestinationAddress UInt32 | |
IpAddrLength UInt32 | |
IPv6SourceAddress Binary | |
IPv6DestinationAddress Binary |
Event ID 1508: Invalid IP option.
#Event ID 1509: Invalid IP hop-by-hop option.
#Event ID 1510: Invalid IP hop-by-hop option.
#Event ID 1511: Invalid IP routing header option.
#Event ID 1512: Invalid IP routing header option.
#Event ID 1513: This option cannot be specified by the user
#Event ID 1514: TCP: interface IfIndex: received potential RSC status indication.
#Description
TCP: interface IfIndex: received potential RSC status indication. Current IPv4 State = TcpRscEnabledIpv4, Offload IPv4 State = OffloadRscEnabledIpv4, Current IPv6 State = TcpRscEnabledIpv6, Offload IPv6 State = OffloadRscEnabledIpv6.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
TcpRscEnabledIpv4 UInt32 | |
OffloadRscEnabledIpv4 UInt32 | |
TcpRscEnabledIpv6 UInt32 | |
OffloadRscEnabledIpv6 UInt32 |
Event ID 1515: UDP: endpoint Endpoint: URO SCU received.
#Event ID 1516: TCP software RSC global disabled mask = TcpRscDisabledMask, UDP software URO global disabled mask = UdpUroDisabledMask.
#Description
TCP software RSC global disabled mask = TcpRscDisabledMask, UDP software URO global disabled mask = UdpUroDisabledMask.
Message #
Fields #
| Name | Description |
|---|---|
TcpRscDisabledMask Int32 | |
UdpUroDisabledMask Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1516",
"version": "0",
"level": "4",
"task": "1486",
"opcode": "0",
"keywords": 9223372586610589824,
"time_created": "2026-03-16T00:21:34.295804400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"TcpRscDisabledMask": "0",
"UdpUroDisabledMask": "48"
},
"message": ""
}
Event ID 1517: UDP: Global parameters updated for Address Family AddressFamily: DisableUro = DisableUro.
#Event ID 1518: IP: IPSNPI client rundown.
#Description
IP: IPSNPI client rundown. AddressFamily Interface = IfIndex, Compartment = CompartmentId, Client = ClientName.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ClientName UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1518,
"version": 0,
"level": 4,
"task": 1202,
"opcode": 0,
"keywords": "0x0000008000000090",
"time_created": "2026-06-02T06:03:32.470+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
},
"execution": {
"process_id": 11500,
"thread_id": 16068
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressFamily": 2,
"ClientName": "SlbNat",
"CompartmentId": 1,
"IfIndex": 1
},
"message": "InterfaceRundown"
}
Event ID 1519: TCPIP: Process with PID=ProcessId, ProcessSeqNum=ProcessSequenceNumber acquired port tracker reservation of type ReservationType, Protocol IPTransportProtocol for NumberOfPorts ports starting at St...
#Description
TCPIP: Process with PID=ProcessId, ProcessSeqNum=ProcessSequenceNumber acquired port tracker reservation of type ReservationType, Protocol IPTransportProtocol for NumberOfPorts ports starting at StartPort with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | |
Status UInt32 | NTSTATUS reference |
ReservationType UInt32 | |
IPTransportProtocol UInt32 | |
StartPort UInt16 | |
NumberOfPorts UInt16 | |
ProcessSequenceNumber UInt64 |
Event ID 1520: Illegal tunnel.
#Event ID 1521: Framing: Interface change in progress.
#Event ID 1522: Framing: Isolation is not supported on this network adapter.
#Event ID 1523: Framing: Failed to set pattern.
#Event ID 1524: Framing: Interface management request.
#Description
Framing: Interface management request. Interface: IfIndex. Address Family: AddressFamily. Request code: FlicCode. Status: NtStatus.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
AddressFamily UInt32 | |
FlicCode UInt32 | |
NtStatus UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1524",
"version": "0",
"level": "4",
"task": "1491",
"opcode": "0",
"keywords": 9223372586610589712,
"time_created": "2026-03-15T23:27:10.979455500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "7392",
"thread_id": "7388"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 4",
"AddressFamily": " 2",
"FlicCode": "0x7",
"NtStatus": "0x0"
},
"message": ""
}
Event ID 1525: Framing: WOL capabilities update in progress.
#Event ID 1526: Framing: A PNP event has been indicated.
#Event ID 1527: Framing: interface rundown: Interface = IfIndex, Luid = IfLuid, Address family = AddressFamily, Compartment = Compartment, Isolation mode = IsolationMode, Isolation ID = IsolalationId, DL address =...
#Description
Framing: interface rundown: Interface = IfIndex, Luid = IfLuid, Address family = AddressFamily, Compartment = Compartment, Isolation mode = IsolationMode, Isolation ID = IsolalationId, DL address = DLAddress, Interface type = InterfaceType, Physical medium type = PhysicalMediumType, SW RSC/URO applicable = SwRscUroApplicable, SW RSC enabled = SwRscEnabled, Alias = IfAlias, SW URO enabled = SwUroEnabled.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
IfLuid UInt64 | |
AddressFamily UInt32 | |
Compartment UInt32 | |
IsolationMode UInt32 | |
IsolalationId UInt32 | |
DlAddrLength UInt32 | |
DLAddress Binary | |
InterfaceType UInt32 | |
PhysicalMediumType UInt32 | |
SwRscUroApplicable UInt32 | |
SwRscEnabled UInt32 | |
IfAlias UnicodeString | |
SwUroEnabled UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1527",
"version": "0",
"level": "4",
"task": "1202",
"opcode": "0",
"keywords": 9223372586610589712,
"time_created": "2026-03-16T00:21:34.295249100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 6",
"IfLuid": "0x6008001000000",
"AddressFamily": " 2",
"Compartment": " 1",
"IsolationMode": " 0",
"IsolalationId": " 0",
"DlAddrLength": " 6",
"DLAddress": "0xBC24119A4DC2",
"InterfaceType": " 6",
"PhysicalMediumType": " 0",
"SwRscUroApplicable": " 1",
"SwRscEnabled": " 0",
"IfAlias": "Ethernet"
},
"message": ""
}
Event ID 1528: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.
#Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
IPTransportProtocol UInt32 | |
NumMessages UInt32 | |
NumBytes UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary |
Event ID 1529: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.
#Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
IPTransportProtocol UInt32 | |
NumMessages UInt32 | |
NumBytes UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddrLength UInt32 | |
RemoteSockAddr Binary |
Event ID 1530: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = EndpointAddress, RemoteAddress = SendAddress) send failed with reason = Reason status = Status.
#Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = EndpointAddress, RemoteAddress = SendAddress) send failed with reason = Reason status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
IPTransportProtocol UInt32 | |
EndpointAddressLength UInt32 | |
EndpointAddress Binary | |
SendAddressLength UInt32 | |
SendAddress Binary | |
Reason UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1531: RAW: endpoint Endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) created.
#Description
RAW: endpoint Endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) created.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
AddressFamily UInt32 | |
IPTransportProtocol UInt32 | |
Compartment UInt32 | |
ProcessId UInt32 | |
ProcessSequenceNumber UInt64 | |
Reason UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1532: RAW: endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) create failed with reason Reason status Status.
#Description
RAW: endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) create failed with reason Reason status Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
AddressFamily UInt32 | |
IPTransportProtocol UInt32 | |
Compartment UInt32 | |
ProcessId UInt32 | |
ProcessSequenceNumber UInt64 | |
Reason UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1533: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bound.
#Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bound.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
IPTransportProtocol UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
Reason UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1534: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bind failed with reason Reason status Status.
#Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bind failed with reason Reason status Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
IPTransportProtocol UInt32 | |
LocalSockAddrLength UInt32 | |
LocalSockAddr Binary | |
Reason UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 1535: RAW: endpoint Endpoint closed.
#Event ID 1536: TCPIP: Error processing router advertisement on interface index IfIndex - Preferred lifetime of PreferredLifetime should not be greater than the valid lifetime of ValidLifetime.
#Event ID 1537: TCPIP: Error processing router advertisement on interface index IfIndex - Prefix length of PrefixLength and identifier of IdentifierLength must add up to the size of an IPv6 ad...
#Event ID 1538: TCPIP: An ARP request was dropped on interface IfIndex.
#Description
TCPIP: An ARP request was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, IP target address = IpTargetAddress, Reason = DropReason.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
DlAddrLength UInt32 | |
DlSourceAddress Binary | |
IpSourceAddress UInt32 | |
IpTargetAddress UInt32 | |
DropReason UInt32 |
Event ID 1539: TCPIP: An ARP reply was dropped on interface IfIndex.
#Description
TCPIP: An ARP reply was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, Directed to this interface = Directed, Reason = DropReason.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
DlAddrLength UInt32 | |
DlSourceAddress Binary | |
IpSourceAddress UInt32 | |
Directed UInt32 | |
DropReason UInt32 |
Event ID 1540: TCPIP: No handler found for an AddressFamily packet with upper layer protocol IPTransportProtocol.
#Event ID 1541: TCPIP: Handler for upper layer protocol IPTransportProtocol for an AddressFamily packet returned with error Status.
#Description
TCPIP: Handler for upper layer protocol IPTransportProtocol for an AddressFamily packet returned with error Status.
Message #
Fields #
| Name | Description |
|---|---|
AddressFamily UInt32 | |
IPTransportProtocol UInt32 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1541",
"version": "0",
"level": "5",
"task": "1496",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-15T23:27:12.462571400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressFamily": " 2",
"IPTransportProtocol": " 6",
"Status": "0x40000026"
},
"message": ""
}
Event ID 1542: IP: neighbor rundown: Interface = IfIndex, Compartment = CompartmentId, IpAddress = IPAddress, DlAddress = DLAddress, State = Neighbor State, LastReachable = LastReachableInMs ms, IsUnreachable = I...
#Description
IP: neighbor rundown: Interface = IfIndex, Compartment = CompartmentId, IpAddress = IPAddress, DlAddress = DLAddress, State = Neighbor State, LastReachable = LastReachableInMs ms, IsUnreachable = IsUnreachable, Flags = Flags.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
CompartmentId UInt32 | |
IpAddrLength UInt32 | |
IPAddress Binary | |
DlAddrLength UInt32 | |
DLAddress Binary | |
NeighborState UInt32 | |
LastReachableInMs UInt32 | |
IsUnreachable UInt32 | |
Flags UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1542",
"version": "0",
"level": "4",
"task": "1497",
"opcode": "0",
"keywords": 9223372586610589728,
"time_created": "2026-03-16T00:21:34.295470700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 1",
"CompartmentId": " 1",
"IpAddrLength": " 16",
"IPAddress": "224.0.0.22",
"DlAddrLength": " 0",
"DLAddress": "",
"Neighbor State": " 6",
"LastReachableInMs": "57839000",
"IsUnreachable": " 0",
"Flags": "0xAC"
},
"message": ""
}
Event ID 1543: TCPIP: An ARP request was dropped on interface IfIndex.
#Description
TCPIP: An ARP request was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, IP target address = IpTargetAddress, Reason = DropReason.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
DlAddrLength UInt32 | |
DlSourceAddress Binary | |
IpSourceAddress UInt32 | |
IpTargetAddress UInt32 | |
DropReason UInt32 |
Event ID 1544: Endpoint Endpoint socket option set with level Level, name Name, value Value.
#Description
Endpoint Endpoint socket option set with level Level, name Name, value Value.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
Level UInt32 | |
Name UInt32 | |
Length UInt32 | |
Value Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1544",
"version": "0",
"level": "4",
"task": "1498",
"opcode": "0",
"keywords": 9223372036854775936,
"time_created": "2026-03-16T00:21:40.064415100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A15F74B50",
"Level": " 41",
"Name": " 27",
"Length": " 4",
"Value": "0x00000000"
},
"message": ""
}
Event ID 1545: TCP: connection = Tcb RACK timeout expired.
#Event ID 1546: TCP: connection = Tcb armed RACK timer.
#Description
TCP: connection = Tcb armed RACK timer. SndUna = SndUna, SndMax = SndMax, SackedBytes = SackedBytes, LossDetected = LossDetected, InRecovery = InRecovery, DeltaTicks = DeltaTicks.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 | |
SackedBytes UInt32 | |
LossDetected UInt32 | |
InRecovery UInt32 | |
DeltaTicks UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1546",
"version": "0",
"level": "4",
"task": "1501",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.488186800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155002622",
"SndMax": "155007102",
"SackedBytes": " 1440",
"LossDetected": " 0",
"InRecovery": " 0",
"DeltaTicks": " 18"
},
"message": ""
}
Event ID 1547: TCP: connection = Tcb received a SACK block.
#Description
TCP: connection = Tcb received a SACK block. SndUna = SndUna, SndMax = SndMax, Ack = Ack, SLE = SLE, SRE = SRE.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 | |
Ack UInt32 | |
SLE UInt32 | |
SRE UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1547",
"version": "0",
"level": "5",
"task": "1502",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.488113200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155002622",
"SndMax": "155007102",
"Ack": "155002622",
"SLE": "155004100",
"SRE": "155005540"
},
"message": ""
}
Event ID 1548: TCP: connection = Tcb received a SACK.
#Description
TCP: connection = received a SACK. SndUna = , SndMax = , Ack = , SackedBytes = , LossDetected = , InRecovery = , NumSackBlocks = , DSackCount = , NewSackInfo = , RecoveryMax = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 | |
Ack UInt32 | |
SackedBytes UInt32 | |
LossDetected UInt32 | |
InRecovery UInt32 | |
NumSackBlocks UInt32 | |
DSackCount UInt32 | |
NewSackInfo UInt32 | |
RecoveryMax UInt32 | |
NewSackedBytes UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1548",
"version": "0",
"level": "4",
"task": "1503",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:27:12.440654000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"SndUna": "4068749001",
"SndMax": "4068767248",
"Ack": "4068749001",
"SackedBytes": " 1460",
"LossDetected": " 1",
"InRecovery": " 0",
"NumSackBlocks": " 1",
"DSackCount": " 0",
"NewSackInfo": " 1",
"RecoveryMax": "4068565828"
},
"message": ""
}
Event ID 1549: TCP: connection = Tcb enabled send tracker.
#Description
TCP: connection = Tcb enabled send tracker.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1549",
"version": "0",
"level": "4",
"task": "1504",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.119290700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0"
},
"message": ""
}
Event ID 1550: TCP: connection = Tcb send tracker acked a transmit.
#Description
TCP: connection = Tcb send tracker acked a transmit. AckNo = AckNo, Start = Start, End = End, Timestamp = Timestamps, EverTransmitted = EverRetransmitted, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
AckNo UInt32 | |
Start UInt32 | |
End UInt32 | |
Timestamps UInt32 | |
EverRetransmitted UInt32 | |
SackedBytes UInt32 | |
BytesInFlight UInt32 | |
State UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1550",
"version": "0",
"level": "5",
"task": "1505",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.268229900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7afb40-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4200",
"thread_id": "7084"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"AckNo": "644687492",
"Start": "644684595",
"End": "644687492",
"Timestamps": "2483305555",
"EverRetransmitted": " 0",
"SackedBytes": " 0",
"BytesInFlight": " 0"
},
"message": ""
}
Event ID 1551: TCP: connection = Tcb send tracker enqueued a transmit.
#Description
TCP: connection = Tcb send tracker enqueued a transmit. Start = Start, End = End, Timestamp = Timestamps, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Start UInt32 | |
End UInt32 | |
Timestamps UInt32 | |
SackedBytes UInt32 | |
BytesInFlight UInt32 | |
NoNewTransmitCreated UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1551",
"version": "0",
"level": "5",
"task": "1506",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.267679100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7afb40-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4200",
"thread_id": "7948"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"Start": "644684595",
"End": "644687492",
"Timestamps": "2483305555",
"SackedBytes": " 0",
"BytesInFlight": " 2897"
},
"message": ""
}
Event ID 1552: TCP: connection = Tcb send tracker marked a transmit as lost.
#Description
TCP: connection = Tcb send tracker marked a transmit as lost. Start = Start, End = End, Timestamp = Timestamps, EverTransmitted = EverRetransmitted, InFlightCount = InFlightCount, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Start UInt32 | |
End UInt32 | |
Timestamps UInt32 | |
EverRetransmitted UInt32 | |
InFlightCount UInt32 | |
SackedBytes UInt32 | |
BytesInFlight UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1552",
"version": "0",
"level": "5",
"task": "1507",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.490313500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6eb8-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Start": "155004062",
"End": "155004100",
"Timestamps": "1924745937",
"EverRetransmitted": " 0",
"InFlightCount": " 0",
"SackedBytes": " 3002",
"BytesInFlight": " 2804"
},
"message": ""
}
Event ID 1553: TCP: accept redirection: original listener = OriginalListener, redirected listener = RedirectedListener, succeeded = Succeeded, redirected = Redirected, codepath = CodePath, local address = SockAdd...
#Description
TCP: accept redirection: original listener = OriginalListener, redirected listener = RedirectedListener, succeeded = Succeeded, redirected = Redirected, codepath = CodePath, local address = SockAddrLength, remote address = LocalSockAddr, redirected address = RemoteSockAddr.
Message #
Fields #
| Name | Description |
|---|---|
OriginalListener Pointer | |
RedirectedListener Pointer | |
Succeeded UInt32 | |
Redirected UInt32 | |
CodePath UInt32 | |
SockAddrLength UInt32 | |
LocalSockAddr Binary | |
RemoteSockAddr Binary | |
RedirectSockAddr Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1553",
"version": "0",
"level": "5",
"task": "1508",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-16T00:21:38.718862500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0ef4b580-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"OriginalListener": "0xFFFF980A0EF4B580",
"RedirectedListener": "0x0",
"Succeeded": " 1",
"Redirected": " 0",
"CodePath": " 2",
"SockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:5985",
"RemoteSockAddr": "10.2.10.11:51201",
"RedirectSockAddr": "0x00000000000000000000000000000000"
},
"message": ""
}
Event ID 1554: TCP: connection = Tcb dropped a SACK block due to SACK limit reached.
#Description
TCP: connection = Tcb dropped a SACK block due to SACK limit reached. SndUna = SndUna, SndMax = SndMax, Ack = Ack, SLE = SLE, SRE = SRE, NumSackedTransmits = NumSackTransmits, limit = Limit.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SndUna UInt32 | |
SndMax UInt32 | |
Ack UInt32 | |
SLE UInt32 | |
SRE UInt32 | |
NumSackTransmits UInt32 | |
Limit UInt32 |
Event ID 1555: TCP: connection Tcb terminated by NSI.
#Event ID 1556: TCP: connection = Tcb rate-based pacing timeout expired.
#Event ID 1557: TCP RLedbat connection = Tcb.
#Description
TCP RLedbat connection = . Type = , SSThresh = , Wnd = , WndWs = , DrainedBytes = , ReceiveHigh = , TsHigh = , LastRollOverTimeMs = , EndReductionTimeMs = , MinDelaySampleMs = , MinBaseDelayMs =.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
EventType UInt32 | |
SsThresh UInt32 | |
Wnd UInt32 | |
WndWs UInt32 | |
DrainedBytes UInt32 | |
ReceiveHigh UInt32 | |
TsHigh UInt32 | |
LastRollOverTimeMs UInt32 | |
EndReductionTimeMs UInt32 | |
MinDelaySampleMs UInt32 | |
MinBaseDelayMs UInt32 |
Event ID 1558: UDP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
#Description
UDP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | |
CurrentLocalAddress Binary | |
ModifiedLocalAddressLength UInt32 | |
ModifiedLocalAddress Binary | |
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
EndpointRestored Boolean |
Event ID 1559: UDP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
#Description
UDP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | |
CurrentLocalAddress Binary | |
ModifiedLocalAddressLength UInt32 | |
ModifiedLocalAddress Binary | |
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
EndpointRestored Boolean |
Event ID 1560: TCP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
#Description
TCP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | |
CurrentLocalAddress Binary | |
ModifiedLocalAddressLength UInt32 | |
ModifiedLocalAddress Binary | |
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
EndpointRestored Boolean |
Event ID 1561: TCP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
#Description
TCP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | |
CurrentLocalAddress Binary | |
ModifiedLocalAddressLength UInt32 | |
ModifiedLocalAddress Binary | |
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
EndpointRestored Boolean |
Event ID 1562: TCP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
#Description
TCP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1563: UDP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
#Description
UDP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
CompartmentId UInt32 | |
AddressFamily UInt32 | |
ProcessStartKey UInt64 |
Event ID 1564: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId ProcessSeqNum=ProcessStartKey) connect failed: access denied.
#Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId ProcessSeqNum=ProcessStartKey) connect failed: access denied.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddressLength UInt32 | |
RemoteAddress Binary | |
Status UInt32 | NTSTATUS reference |
ProcessId UInt32 | |
Compartment UInt32 | |
Tcb Pointer | |
ProcessStartKey UInt64 |
Event ID 1565: TCP: Congestion state changed for connection = Tcb from OldState = OldState to NewState = NewState.
#Event ID 1566: TCP: connection = Tcb detected reordering.
#Event ID 1577: TCP: connection = Tcb updated reownd.
#Description
TCP: connection = updated reownd. Multiplier = , Persist = , Reownd = , ReorderingSeen = , DSackSeenOnLatestAck = , InLossRecovery = , DupAckCountReached = , DSackRound = , DSackRoundValid = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Multiplier UInt32 | |
Persist UInt32 | |
Reownd UInt32 | |
ReorderingSeen UInt32 | |
DSackSeenOnLatestAck UInt32 | |
InLossRecovery UInt32 | |
DupAckCountReached UInt32 | |
DSackRound UInt32 | |
DSackRoundValid UInt32 |
Event ID 1578: IP: Injecting NBL Nbl on send path.
#Event ID 1579: IP: Injecting NBL Nbl on raw send path.
#Event ID 1580: IP: Injecting NBL Nbl on receive path.
#Event ID 1581: IP: Injecting NBL Nbl on forward path.
#Event ID 1582: IP: Indication filtered because destination interface IfIndex is not contained in IF list.
#Event ID 1583: BBR2: TCB Tcb bbr_bw bbr_bw min_rtt_us min_rtt_us mode mode cycle_idx cycle_idx CWnd CWnd PacingRate PacingRate BytesSent BytesSent SRtt SRtt.
#Description
BBR2: TCB Tcb bbr_bw bbr_bw min_rtt_us min_rtt_us mode mode cycle_idx cycle_idx CWnd CWnd PacingRate PacingRate BytesSent BytesSent SRtt SRtt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
bbr_bw UInt32 | |
min_rtt_us UInt32 | |
mode UInt32 | |
cycle_idx UInt32 | |
CWnd UInt32 | |
PacingRate UInt32 | |
BytesSent UInt32 | |
SRtt UInt32 |
Event ID 1584: TCP: connection = Tcb send tracker marked a transmit as rexmit.
#Description
TCP: connection = Tcb send tracker marked a transmit as rexmit. Start = Start, End = End, Timestamp = Timestamps, InFlightCount = InFlightCount, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Start UInt32 | |
End UInt32 | |
Timestamps UInt32 | |
InFlightCount UInt32 | |
SackedBytes UInt32 | |
BytesInFlight UInt32 |
Event ID 1585: TCP: connection = Tcb send tracker update RACK info.
#Description
TCP: connection = Tcb send tracker update RACK info. RackXmitTimeStampValid = RackXmitTimeStampValid, RackXmitTimeStampInUs = RackXmitTimeStampInUs, RackEndSeq = RackEndSeq, RackRttInUs = RackRttInUs, NowInUs = NowInUs, TimeStampInUs = TimeStampInUs.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
RackXmitTimeStampValid UInt32 | |
RackXmitTimeStampInUs UInt32 | |
RackEndSeq UInt32 | |
RackRttInUs UInt32 | |
NowInUs UInt32 | |
TimeStampInUs UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1585,
"version": 0,
"level": 5,
"task": 1527,
"opcode": 0,
"keywords": "0x0000000100000000",
"time_created": "2026-06-02T06:03:34.154+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{F76423D8-BD09-FFFF-0000-000000000000}"
},
"execution": {
"process_id": 2764,
"thread_id": 812
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"NowInUs": 3164724227,
"RackEndSeq": 2424967783,
"RackRttInUs": 1236,
"RackXmitTimeStampInUs": 3164722991,
"RackXmitTimeStampValid": 1,
"Tcb": "0xFFFFBD09F7642010",
"TimeStampInUs": 3164722991
},
"message": "TcpSendTrackerRackUpdate"
}
Event ID 1586: IP: Prefix sharing now PrefixSharing on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily.
#Description
IP: Prefix sharing now PrefixSharing on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily. Updating shared prefixes and resetting autoconfigured state, such as addresses and routes.
Message #
Fields #
| Name | Description |
|---|---|
AddressFamily UInt32 | |
CompartmentId UInt32 | |
Interface UInt32 | |
PrefixSharing UInt32 |
Event ID 1587: TCP: connection Tcb received a careful ACK.
#Description
TCP: connection Tcb received a careful ACK. ThAck = ThAck, SndUna = SndUna, SndMax = SndMax, RecoveryMax = RecoveryMax, SndWnd = SndWnd, SndWndChanged = SndWndChanged, SackUpdated = SackUpdated, State = TcpState, CongestionState = CongestionState, F-RTO = Frto.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
ThAck UInt32 | |
SndUna UInt32 | |
SndMax UInt32 | |
RecoveryMax UInt32 | |
SndWnd UInt32 | |
SndWndChanged UInt32 | |
SackUpdated UInt32 | |
TcpState UInt32 | |
CongestionState UInt32 | |
Frto UInt32 |
Event ID 1588: IP: Forwarding tag on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily changed from OldForwardingTag to NewForwardingTag.
#Event ID 1589: TCP: AF AddressFamily, RssEnabled = RssEnabled .
#Description
TCP: AF AddressFamily, RssEnabled = RssEnabled .
Message #
Fields #
| Name | Description |
|---|---|
AddressFamily UInt32 | |
RssEnabled UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1589,
"version": 0,
"level": 4,
"task": 1530,
"opcode": 0,
"keywords": "0x0000000000000080",
"time_created": "2026-06-02T06:03:32.469+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{E27FDE20-BD09-FFFF-0000-000000000000}"
},
"execution": {
"process_id": 11500,
"thread_id": 16068
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressFamily": 23,
"RssEnabled": 1
},
"message": "TcpAfRundown"
}
Event ID 1590: TCP: connection = Tcb send completion failed.
#Description
TCP: connection = Tcb send completion failed. NBL = Nbl, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
Nbl Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 1591: TCPIP: Alloc hooks setup: Status = Status.
#Description
TCPIP: Alloc hooks setup: Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 1592: IP: Neighbor with IpAddress = IPAddress DlAddress = DLAddress on Interface = Interface was reset while in state OldNeighborState due to Reason = ResetReason.
#Description
IP: Neighbor with IpAddress = IPAddress DlAddress = DLAddress on Interface = Interface was reset while in state OldNeighborState due to Reason = ResetReason.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
IpAddrLength UInt32 | |
IPAddress Binary | |
DlAddrLength UInt32 | |
DLAddress Binary | |
OldNeighborState UInt32 | |
ResetReason UInt32 | |
CompartmentId UInt32 |
Event ID 1593: TCP: Global timer fired, Processor = Processor, Tick = Tick.
#Event ID 1594: TCP: Global timer armed, NextToExpire = NextToExpire, Period = Period.
#Event ID 1597: TCP: paused receive buffer growth for high memory usage, AF = AddressFamily, TCB = Tcb, TotalBytesBuffered = TotalBytesBuffered, UpperLimit = UpperLimit.
#Event ID 1598: IP: Autoconfigured address creation failed due to autoconfiguration limit, Address = IPv4Address IPProtocol IPv6Address, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.
#Description
IP: Autoconfigured address creation failed due to autoconfiguration limit, Address = IPv4Address IPProtocol IPv6Address, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
CompartmentId UInt32 | |
Protocol AnsiString | Known values
|
IpAddrLength UInt32 | |
IPv4Address UInt32 | |
IPv6Address Binary | |
IPProtocol UInt32 |
Event ID 1599: IP: Autoconfigured route creation failed due to autoconfiguration limit, DestinationPrefix = IPv4DestinationPrefix IPProtocol DestinationPrefix /DestinationPrefixLength, Nexthop = IPv4NextHopAddres...
#Description
IP: Autoconfigured route creation failed due to autoconfiguration limit, DestinationPrefix = IPv4DestinationPrefix IPProtocol DestinationPrefix /DestinationPrefixLength, Nexthop = IPv4NextHopAddress IPProtocol NextHopAddress, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
CompartmentId UInt32 | |
Protocol AnsiString | Known values
|
DestinationPrefixAddressLength UInt32 | |
NextHopAddressLength UInt32 | |
DestinationPrefixLength UInt32 | |
DestinationPrefix Binary | |
NextHopAddress Binary | |
IPv4DestinationPrefix UInt32 | |
IPv4NextHopAddress UInt32 | |
IPProtocol UInt32 |
Event ID 1600: IP: Policy based routing failed - Compartment: Compartment DstAddr: DestinationAddress SrcAddr: SourceAddress TransProto: TransportProtocol IcmpType: IcmpType IcmpCode: IcmpCode PolicySrcAddr: Poli...
#Description
IP: Policy based routing failed - Compartment: DstAddr: SrcAddr: TransProto: IcmpType: IcmpCode: PolicySrcAddr: PolicyNextHopAddr: PolicyIfIndex: FailureReason: Status.
Message #
Fields #
| Name | Description |
|---|---|
Compartment UInt32 | |
DestinationAddrLength UInt32 | |
DestinationAddress Binary | |
SourceAddrLength UInt32 | |
SourceAddress Binary | |
TransportProtocol UInt32 | |
IcmpType UInt8 | |
IcmpCode UInt8 | |
PolicySourceAddrLength UInt32 | |
PolicySourceAddress Binary | |
PolicyNextHopAddrLength UInt32 | |
PolicyNextHopAddress Binary | |
PolicyInterfaceLuid UInt64 | |
FailureReason UInt32 | Known values
|
Status UInt32 | NTSTATUS reference |
Event ID 1601: TCP: connection Tcb in NewState received NBL NBL in FastPath = FastPath Seq = ThSeq Ack = ThAck Flags = ThFlags RSC = RSC CoalescedSegCount = CoalescedSegCount RscTcpTimestampDelta = RscTcpTimestam...
#Description
TCP: connection Tcb in NewState received NBL NBL in FastPath = FastPath Seq = ThSeq Ack = ThAck Flags = ThFlags RSC = RSC CoalescedSegCount = CoalescedSegCount RscTcpTimestampDelta = RscTcpTimestampDelta EcnCePresent = EcnCePresent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NewState UInt32 | |
FastPath UInt32 | |
NBL Pointer | |
ThSeq UInt32 | |
ThAck UInt32 | |
ThFlags UInt8 | |
RSC UInt32 | |
CoalescedSegCount UInt16 | |
RscTcpTimestampDelta UInt32 | |
EcnCePresent UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1601,
"version": 0,
"level": 5,
"task": 1601,
"opcode": 0,
"keywords": "0x0000000200000000",
"time_created": "2026-06-02T06:03:34.154+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
},
"execution": {
"process_id": 2764,
"thread_id": 812
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"CoalescedSegCount": 1,
"EcnCePresent": 0,
"FastPath": 1,
"NBL": "0xFFFFBD09F35BD070",
"NewState": 4,
"RSC": 0,
"RscTcpTimestampDelta": 0,
"Tcb": "0xFFFFBD09F7642010",
"ThAck": 2424967783,
"ThFlags": 16,
"ThSeq": 3278916547
},
"message": "TcpRx"
}
Event ID 1602: TCP: connection Tcb process fast RX batch SegmentCount = SegmentCount NumBytes = NumBytes NblHead = NblHead NblTail = NblTail Inspect = Inspect.
#Description
TCP: connection Tcb process fast RX batch SegmentCount = SegmentCount NumBytes = NumBytes NblHead = NblHead NblTail = NblTail Inspect = Inspect.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SegmentCount UInt32 | |
NumBytes UInt32 | |
NblHead Pointer | |
NblTail Pointer | |
Inspect UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1602,
"version": 0,
"level": 5,
"task": 1602,
"opcode": 0,
"keywords": "0x0000000200000000",
"time_created": "2026-06-02T06:03:34.157+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
},
"execution": {
"process_id": 10696,
"thread_id": 5148
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"Inspect": 1,
"NblHead": "0xFFFFBD09F35BD070",
"NblTail": "0xFFFFBD09F3386D20",
"NumBytes": 4874,
"SegmentCount": 5,
"Tcb": "0xFFFFBD09F7642010"
},
"message": "TcpProcessFastRxBatch"
}
Event ID 1603: TCP: connection Tcb in State Injected disconnect DataLength=DataLength.
#Event ID 1604: NDKPI Disconnect Event CallbackEx: DisconnectEventContext DisconnectEventContext ProviderDisconnectReason ProviderDisconnectReason.
#Event ID 1605: NDKPI AcceptEx: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
#Description
NDKPI AcceptEx: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | |
NdkQp Pointer | |
IRD UInt32 | |
ORD UInt32 | |
DisconnectEventContext Pointer | |
RequestContext Pointer | |
PrivateDataLength UInt32 |
Event ID 1606: NDKPI CompleteConnectEx: RequestContext RequestContext Connector NdkConnector DisconnectEventContext DisconnectEventContext.
#Event ID 1607: NDKPI Open Adapter Version Override: IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.
#Description
NDKPI Open Adapter Version Override: IF_INDEX ProviderSupportedNDKVersion {.} FlConfiguredNdkpiVersion {.} ActualSupportedVersion {.}.
Message #
Fields #
| Name | Description |
|---|---|
ProviderSupportedNDKVersionMajor UInt16 | |
ProviderSupportedNDKVersionMinor UInt16 | |
FlConfiguredNdkpiVersionMajor UInt16 | |
FlConfiguredNdkpiVersionMinor UInt16 | |
ActualSupportedNDKVersionMajor UInt16 | |
ActualSupportedNDKVersionMinor UInt16 | |
IF_INDEX UInt32 |
Event ID 1608: Fl Reload Registry Config: Override Status: OverrideStatus OldFlConfiguredVersion {OldFlVersionMajor.
#Description
Fl Reload Registry Config: Override Status: OverrideStatus OldFlConfiguredVersion {OldFlVersionMajor.OldFlVersionMinor} NewFlConfiguredVersion {NewFlVersionMajor.NewFlVersionMinor}.
Message #
Fields #
| Name | Description |
|---|---|
OldFlVersionMajor UInt16 | |
OldFlVersionMinor UInt16 | |
NewFlVersionMajor UInt16 | |
NewFlVersionMinor UInt16 | |
OverrideStatus UnicodeString |
Event ID 1609: NDKPI Open Adapter: Unexpected version returned by provider, IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.
#Description
NDKPI Open Adapter: Unexpected version returned by provider, IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.ProviderSupportedNDKVersionMinor} ConsumerSpecifiedVersion {ConsumerSpecifiedNdkpiVersionMajor.ConsumerSpecifiedNdkpiVersionMinor}.
Message #
Fields #
| Name | Description |
|---|---|
ProviderSupportedNDKVersionMajor UInt16 | |
ProviderSupportedNDKVersionMinor UInt16 | |
ConsumerSpecifiedNdkpiVersionMajor UInt16 | |
ConsumerSpecifiedNdkpiVersionMinor UInt16 | |
IF_INDEX UInt32 |
Event ID 1610: TCPIP: Disconnected Standby traffic.
#Event ID 1611: TCPIP: Disconnected Standby (DS) transition detected.
#Event ID 1612: ResetResolve API call: ProcessName API.
#Event ID 1613: USO global disabled mask = UdpUsoDisabledMask.
#Description
USO global disabled mask = UdpUsoDisabledMask.
Message #
Fields #
| Name | Description |
|---|---|
UdpUsoDisabledMask Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1613,
"version": 0,
"level": 4,
"task": 1613,
"opcode": 0,
"keywords": "0x0000008000000080",
"time_created": "2026-06-02T06:03:32.471+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
},
"execution": {
"process_id": 11500,
"thread_id": 16068
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"UdpUsoDisabledMask": 0
},
"message": "SendOffloadGlobalState"
}
Event ID 1614: Framing: SW URO SwUroEnabled, HW URO HwUroEnabled.
#Event ID 1615: Tcpip Power Policy set to: PowerPolicy.
#Event ID 1616: Router Solicitation sent.
#Event ID 1617: Router Solicitation requested on dormant interface.
#Event ID 1618: IP: Route lifetime refresh.
#Description
IP: Route lifetime refresh. Interface = Interface, Protocol = Protocol, Compartment = Compartment, Prefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Metric = Metric, Origin = Origin, CurrentTime = CurrentTime, Old BaseTime = OldBasetime, Old ValidTime = OldValidTime, Old PreferredTime = OldPreferredTime, New BaseTime = NewBasetime, New ValidTime = NewValidTime, New PreferredTime = NewPreferredTime.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | |
Protocol AnsiString | Known values
|
Compartment UInt32 | |
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
DestinationPrefixLength UInt32 | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
Metric UInt32 | |
Origin UInt32 | |
CurrentTime UInt32 | |
OldBasetime UInt32 | |
OldValidTime UInt32 | |
OldPreferredTime UInt32 | |
NewBasetime UInt32 | |
NewValidTime UInt32 | |
NewPreferredTime UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1618,
"version": 0,
"level": 4,
"task": 1618,
"opcode": 0,
"keywords": "0x0000008000000020",
"time_created": "2026-06-02T06:03:39.063+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
},
"execution": {
"process_id": 17168,
"thread_id": 16688
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"Compartment": 1,
"CurrentTime": 246857,
"DestinationPrefix": "02000000000000000000000000000000",
"DestinationPrefixAddressLength": 16,
"DestinationPrefixLength": 0,
"Interface": 11,
"Metric": 256,
"New Basetime": 246857,
"New PreferredTime": 4294967295,
"New ValidTime": 4294967295,
"NextHopAddress": "020000000A020AFE0000000000000000",
"NextHopAddressLength": 16,
"Old Basetime": 246797,
"Old PreferredTime": 4294967295,
"Old ValidTime": 4294967295,
"Origin": 0,
"Protocol": "IPv4"
},
"message": "TcpipIpRouteLifetime"
}
Event ID 1619: IP: Constraint computation (unused) - Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason...
#Description
IP: Constraint computation (unused) - Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName (Rule Rule.RuleExtension).
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | |
PreferredSourceIPAddress Binary | |
NonPreferredSourceIPAddress Binary | |
DestinationIPAddress Binary | |
CompartmentId UInt32 | |
Rule UInt32 | |
RuleExtension UInt32 | |
RuleName UInt32 |
Event ID 1620: WFP-ALE: RemoteEndPoint Cleanup: (local=LocalAddress remote=RemoteAddress) currentTick=CurrentTick lastTick=LastTick lifeTime=LifeTime LifetimeFactor=LifetimeFactor.
#Description
WFP-ALE: RemoteEndPoint Cleanup: (local=LocalAddress remote=RemoteAddress) currentTick=CurrentTick lastTick=LastTick lifeTime=LifeTime LifetimeFactor=LifetimeFactor.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | |
LocalAddress Binary | |
RemoteAddress Binary | |
CurrentTick UInt64 | |
LastTick UInt64 | |
LifeTime UInt32 | |
LifetimeFactor UInt16 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1620,
"version": 0,
"level": 4,
"task": 1620,
"opcode": 0,
"keywords": "0x0000000000008000",
"time_created": "2026-06-02T06:03:37.765+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
},
"execution": {
"process_id": 9180,
"thread_id": 17448
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressLength": 16,
"CurrentTick": 123427397,
"LastTick": 123307081,
"LifeTime": 60,
"LifetimeFactor": 1,
"LocalAddress": "020000000A020A6F0000000000000000",
"RemoteAddress": "02000001080808080000000000000000"
},
"message": "RemoteEndpointCleanup"
}
Event ID 1621: FL: Virtual interface creation.
#Description
FL: Virtual interface creation. Interface = IfLuid, Family = AddressFamily, CompartmentGuid = CompartmentGuid, CompartmentId = CompartmentId, IsolationMode = IsolationMode, IsolationId = IsolalationId, Origin = Origin, VirtualIfLuid = VirtualIfLuid, VirtualIfIndex = VirtualIfIndex.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | |
AddressFamily UInt32 | |
CompartmentGuid GUID | |
CompartmentId UInt32 | |
IsolationMode UInt32 | |
IsolalationId UInt32 | |
Origin UInt32 | |
VirtualIfLuid UInt64 | |
VirtualIfIndex UInt32 |
Event ID 1622: FL: Virtual interface deletion.
#Description
FL: Virtual interface deletion. Interface = IfLuid, Family = AddressFamily, CompartmentGuid = CompartmentGuid, CompartmentId = CompartmentId, IsolationMode = IsolationMode, IsolationId = IsolalationId, Origin = Origin, VirtualIfLuid = VirtualIfLuid, VirtualIfIndex = VirtualIfIndex.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | |
AddressFamily UInt32 | |
CompartmentGuid GUID | |
CompartmentId UInt32 | |
IsolationMode UInt32 | |
IsolalationId UInt32 | |
Origin UInt32 | |
VirtualIfLuid UInt64 | |
VirtualIfIndex UInt32 |
Event ID 1623: Tcpip Power Policy Standby-to-Full-Power transition detected.
#Description
Tcpip Power Policy Standby-to-Full-Power transition detected. Lifetimes adjusted for Interface:InterfaceIndex, DestinationPrefix:DestinationPrefix/DestinationPrefixLength, NextHopAddress:NextHopAddress, EnteredStandbySystemTickCount:EnteredStandbySystemTickCount, CurrentTickCount:CurrentTickCount, ValidLifetimeHighWaterTickCount:ValidLifetimeHighWaterTickCount
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
DestinationPrefixAddressLength UInt32 | |
DestinationPrefix Binary | |
DestinationPrefixLength UInt32 | |
NextHopAddressLength UInt32 | |
NextHopAddress Binary | |
EnteredStandbySystemTickCount UInt64 | |
CurrentTickCount UInt32 | |
ValidLifetimeHighWaterTickCount UInt32 |
Event ID 1624: TCP: connection Tcb: flow label refreshed, old = OldFlowLabel new = NewFlowLabel.
#Event ID 1625: TCP: Connection Tcb send idle triggered.
#Description
TCP: Connection Tcb send idle triggered. OldCwnd = OldCwnd, NewCwnd = NewCwnd, CurrentTick = CurrentTick, IdleTick = IdleTick, RTO = Rto.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
OldCwnd UInt32 | |
NewCwnd UInt32 | |
Processor UInt32 | |
CurrentTick UInt32 | |
IdleTick UInt32 | |
Rto UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1625,
"version": 0,
"level": 4,
"task": 1221,
"opcode": 0,
"keywords": "0x0000000100000000",
"time_created": "2026-06-02T06:03:34.152+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
},
"execution": {
"process_id": 2940,
"thread_id": 13708
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"CurrentTick": 123423807,
"IdleTick": 123421941,
"NewCwnd": 269440,
"OldCwnd": 269440,
"Processor": 0,
"Rto": 300,
"Tcb": "0xFFFFBD09F7642010"
},
"message": "TcpCwndRestart"
}
Event ID 1626: TCP: connection Tcb: bytes limited by sender = SenderLimitedBytes receiver = ReceiverLimitedBytes congestion = CongestionLimitedBytes.
#Description
TCP: connection Tcb: bytes limited by sender = SenderLimitedBytes receiver = ReceiverLimitedBytes congestion = CongestionLimitedBytes.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
SenderLimitedBytes UInt64 | |
ReceiverLimitedBytes UInt64 | |
CongestionLimitedBytes UInt64 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1626,
"version": 0,
"level": 5,
"task": 1626,
"opcode": 0,
"keywords": "0x0000000100000000",
"time_created": "2026-06-02T06:03:34.153+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
},
"execution": {
"process_id": 2940,
"thread_id": 13708
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"CongestionLimitedBytes": 0,
"ReceiverLimitedBytes": 0,
"SenderLimitedBytes": 2328397,
"Tcb": "0xFFFFBD09F7642010"
},
"message": "TcpLimitingFactor"
}
Event ID 1627: UDP: ChangeReason scheduled HW URO to be NewUroState on interface IfLuid.
#Description
UDP: ChangeReason scheduled HW URO to be NewUroState on interface IfLuid. CurrentState:CurrentUroState. Last scheduled state: LastScheduledState.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | |
ChangeReason UInt32 | |
NewUroState UInt32 | |
CurrentUroState UInt32 | |
LastScheduledState UInt32 | |
FailureReasonFlags UInt32 |
Event ID 1628: UDP: ChangeReason NewUroState HW URO on interface IfLuid.
#Description
UDP: ChangeReason NewUroState HW URO on interface IfLuid. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | |
ChangeReason UInt32 | |
NewUroState UInt32 | |
Status UInt32 | NTSTATUS reference |
FailureReasonFlags UInt32 |
Event ID 1629: FL: FLSNPI client attach.
#Description
FL: FLSNPI client attach. Client: ClientName, AddressFamily: AddressFamily, NpiVersion: ClientNpiVersion, NblContextSize: NblContextSize, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
AddressFamily UInt32 | |
ClientNpiVersion UInt32 | |
NblContextSize UInt32 | |
FailureReason UInt32 | Known values
|
Status UInt32 | NTSTATUS reference |
Event ID 1630: FL: FLSNPI client detach.
#Event ID 1631: FL: FLSNPI client interface attach.
#Description
FL: FLSNPI client interface attach. Client: ClientName, AddressFamily: AddressFamily, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
AddressFamily UInt32 | |
CompartmentId UInt32 | |
IfIndex UInt32 | |
VirtualIfId UInt32 | |
Flags UInt32 | |
FailureReason UInt32 | Known values
|
Status UInt32 | NTSTATUS reference |
Event ID 1632: FL: FLSNPI client interface detach.
#Description
FL: FLSNPI client interface detach. Client: ClientName, AddressFamily: AddressFamily, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
AddressFamily UInt32 | |
CompartmentId UInt32 | |
IfIndex UInt32 | |
VirtualIfId UInt32 | |
FailureReason UInt32 | Known values
|
Status UInt32 | NTSTATUS reference |
Flags UInt32 |
Event ID 1633: FL: FLSNPI datapath failure.
#Description
FL: FLSNPI datapath failure. Operation: Operation, AddressFamily: AddressFamily, Direction: PathDirection, Client:ClientName, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, InjectIfIndex: InjectionIfIndex, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Operation UInt32 | Known values
|
AddressFamily UInt32 | |
PathDirection UInt32 | |
ClientName UnicodeString | |
CompartmentId UInt32 | |
IfIndex UInt32 | |
VirtualIfId UInt32 | |
Flags UInt32 | |
FailureReason UInt32 | Known values
|
Status UInt32 | NTSTATUS reference |
InjectionIfIndex UInt32 |
Event ID 1634: FL: FLSNPI client silent drop.
#Description
FL: FLSNPI client silent drop. Direction: PathDirection, AddressFamily:AddressFamily, Client: ClientName, CompartmentId: CompartmentId, IfIndex: InterfaceIndex, VirtualIfId: VirtualIfId, PacketCount: PacketCount.
Message #
Fields #
| Name | Description |
|---|---|
PathDirection UInt32 | |
AddressFamily UInt32 | |
ClientName UnicodeString | |
CompartmentId UInt32 | |
InterfaceIndex UInt32 | |
VirtualIfId UInt32 | |
PacketCount UInt32 |
Event ID 1635: FL: FLSNPI indication stats.
#Description
FL: FLSNPI indication stats. Direction: Direction, AddressFamily:AddressFamily, CompartmentId: CompartmentId, IfIndex: InterfaceIndex, VirtualIfId: VirtualIfId, PacketsIndicated: PacketsIndicated, PacketsReturned: PacketsReturned, PacketsInjected: PacketsInjected, PacketsCloned: PacketsCloned, PacketsClonedForSplitNB: PacketsClonedWithNBSplit, PacketsDropped: PacketsDropped, PacketsSilentlyDropped: PacketsSilentlyDropped.
Message #
Fields #
| Name | Description |
|---|---|
Direction UInt32 | Known values
|
AddressFamily UInt32 | |
CompartmentId UInt32 | |
InterfaceIndex UInt32 | |
VirtualIfId UInt32 | |
PacketsIndicated UInt32 | |
PacketsReturned UInt32 | |
PacketsInjected UInt32 | |
PacketsCloned UInt32 | |
PacketsClonedWithNBSplit UInt32 | |
PacketsDropped UInt32 | |
PacketsSilentlyDropped UInt32 |
Event ID 1636: TCPIP: Current Power Policy : PowerPolicy.
#Description
TCPIP: Current Power Policy : PowerPolicy.
Message #
Fields #
| Name | Description |
|---|---|
PowerPolicy UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1636,
"version": 0,
"level": 4,
"task": 1636,
"opcode": 0,
"keywords": "0x0000008000000000",
"time_created": "2026-06-02T06:03:32.471+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
},
"execution": {
"process_id": 11500,
"thread_id": 16068
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"PowerPolicy": 1
},
"message": "TcpipPowerPolicyRundown"
}
Event ID 1637: TCP: connection Tcb send acked NumBytes bytes starting from SndNxt ActivityID = ActivityID.
#Description
TCP: connection Tcb send acked NumBytes bytes starting from SndNxt ActivityID = ActivityID.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | |
NumBytes UInt32 | |
SndNxt UInt32 | |
ActivityID Pointer | |
SndLimBytesSnd UInt64 | |
SndLimBytesRwin UInt64 | |
SndLimBytesCwnd UInt64 | |
CWnd UInt32 | |
SRtt UInt32 | |
LossRecoveryEpisodes UInt32 | |
RtoEpisodes UInt32 | |
PtoEpisodes UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
"event_source_name": "",
"event_id": 1637,
"version": 0,
"level": 4,
"task": 1637,
"opcode": 0,
"keywords": "0x0000400100000000",
"time_created": "2026-06-02T06:03:34.154+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
},
"execution": {
"process_id": 2764,
"thread_id": 812
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"ActivityID": "0xFFFFBD09E5A7D5B0",
"CWnd": 269440,
"LossRecoveryEpisodes": 0,
"NumBytes": 1564,
"PtoEpisodes": 0,
"RtoEpisodes": 0,
"SRtt": 2444,
"SndLimBytesCwnd": 0,
"SndLimBytesRwin": 0,
"SndLimBytesSnd": 2328397,
"SndNxt": 2424966219,
"Tcb": "0xFFFFBD09F7642010"
},
"message": "TcpSendAcked"
}
Event ID 1638: IP: Event.
#Description
IP: Event. Interface = Interface, Compartment = CompartmentId, RouterAddress = RouterAddress, Prefix = Prefix/PrefixLength, Lifetime = Lifetime.
Message #
Fields #
| Name | Description |
|---|---|
Event UInt32 | |
Interface UInt32 | |
CompartmentId UInt32 | |
RouterAddrLength UInt32 | |
RouterAddress Binary | |
PrefixAddrLength UInt32 | |
Prefix Binary | |
PrefixLength UInt32 | |
Lifetime UInt32 |
Event ID 1638: IP:
#Description
IP: . Interface = , Compartment = , RouterAddress = , Prefix = /, Lifetime = .
Fields #
| Name | Description |
|---|---|
Event UInt32 | |
Interface UInt32 | |
CompartmentId UInt32 | |
RouterAddrLength UInt32 | |
RouterAddress Binary | |
PrefixAddrLength UInt32 | |
Prefix Binary | |
PrefixLength UInt32 | |
Lifetime UInt32 |
Event ID 1639: IP: Destination cache invalidated.
#Event ID 1639: IP: Destination cache invalidated
#Description
IP: Destination cache invalidated. Compartment = , Family = , RoutingEpoch = .
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | |
AddressFamily UInt32 | |
RoutingEpoch Int32 |
Event ID 1640: FL: Virtual interface set failed.
#Description
FL: Virtual interface set failed. NsiAction = NsiAction, Family AddressFamily, IfLuid = IfLuid, CompartmentGuid = CompartmentGuid, VirtualIfId = VirtualIfId, IsolationMode = IsolationMode, Status = Status, Reason = FailureReason.
Message #
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | |
AddressFamily UInt32 | |
IfLuid UInt64 | |
CompartmentGuid GUID | |
VirtualIfId UInt32 | |
IsolationMode UInt32 | |
Status UInt32 | NTSTATUS reference |
FailureReason UInt32 | Known values
|
Event ID 1640: FL: Virtual interface set failed
#Description
FL: Virtual interface set failed. NsiAction = , Family , IfLuid = , CompartmentGuid = , VirtualIfId = , IsolationMode = , Status = , Reason =.
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | |
AddressFamily UInt32 | |
IfLuid UInt64 | |
CompartmentGuid GUID | |
VirtualIfId UInt32 | |
IsolationMode UInt32 | |
Status UInt32 | NTSTATUS reference |
FailureReason UInt32 | Known values
|
Event ID 1641: FL: Virtual interface get failed.
#Description
FL: Virtual interface get failed. NsiAction = NsiAction, Family AddressFamily, IfLuid = IfLuid, CompartmentGuid = CompartmentGuid, VirtualIfId = VirtualIfId, IsolationMode = IsolationMode, Status = Status, Reason = FailureReason.
Message #
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | |
AddressFamily UInt32 | |
IfLuid UInt64 | |
CompartmentGuid GUID | |
VirtualIfId UInt32 | |
IsolationMode UInt32 | |
Status UInt32 | NTSTATUS reference |
FailureReason UInt32 | Known values
|
Event ID 1641: FL: Virtual interface get failed
#Description
FL: Virtual interface get failed. NsiAction = , Family , IfLuid = , CompartmentGuid = , VirtualIfId = , IsolationMode = , Status = , Reason =.
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | |
AddressFamily UInt32 | |
IfLuid UInt64 | |
CompartmentGuid GUID | |
VirtualIfId UInt32 | |
IsolationMode UInt32 | |
Status UInt32 | NTSTATUS reference |
FailureReason UInt32 | Known values
|
Event ID 1642: IP: Received Prefix Option in Router Advertisement.
#Description
IP: Received Prefix Option in Router Advertisement. Interface(Index/GUID) = InterfaceIndex/InterfaceGuid, Compartment = CompartmentId, SourceIpAddress = SourceIpAddress, Prefix(Value/Length) = PrefixValue/PrefixLength, Lifetimes(Valid/Preferred) = ValidLifetime/PreferredLifetime, Flags = FlagsValue (Route = IsRoute, SitePrefix = IsSitePrefix, RouterAddress = IsRouterAddress, Autonomous = IsAutonomous, OnLink = IsOnLink)
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
InterfaceGuid GUID | |
CompartmentId UInt32 | |
AddressLength UInt32 | |
SourceIpAddress Binary | |
PrefixValue Binary | |
PrefixLength UInt32 | |
ValidLifetime UInt32 | |
PreferredLifetime UInt32 | |
FlagsValue UInt8 | |
IsRoute Boolean | |
IsSitePrefix Boolean | |
IsRouterAddress Boolean | |
IsAutonomous Boolean | |
IsOnLink Boolean |
Event ID 1642: IP: Received Prefix Option in Router Advertisement
#Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | |
InterfaceGuid GUID | |
CompartmentId UInt32 | |
AddressLength UInt32 | |
SourceIpAddress Binary | |
PrefixValue Binary | |
PrefixLength UInt32 | |
ValidLifetime UInt32 | |
PreferredLifetime UInt32 | |
FlagsValue UInt8 | |
IsRoute Boolean | |
IsSitePrefix Boolean | |
IsRouterAddress Boolean | |
IsAutonomous Boolean | |
IsOnLink Boolean |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {2F07E2EE-15DB-40F1-90EF-9D7BA282188A}
Defined in tcpip.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.4297, captured 2026-06-02
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.5074, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4297, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02