Microsoft-Windows-TerminalServices-ClientActiveXCore

75 events across 3 channels

EventTitleChannelSample
225StateTransitionName: Transitioned successfully from PreviousStateName to …DebugN
226StateTransitionName: An error was encountered when transitioning from …OperationalY
227StateTransitionName: MCS Channel Join Confirmation received: ChannelID = …DebugN
1000task_0DebugN
1001RDP ClientActiveX is trying to connect to the server (Value).AnalyticN
1002RDP ClientActiveX has connected to the serverAnalyticN
1003RDP ClientActiveX has been disconnected (Reason= Value).AnalyticN
1004Client has logged on to the server (SessionId = Value).AnalyticN
1005Client failed to logon on to the server (Error = ErrorCode).AnalyticN
1006Client machine has lost network connectivity (Reason= ErrorCode).AnalyticN
1007DNS failed to resolve the server name (Error= ErrorCode).OperationalN
1008The credentials provided are authenticated by the serverAnalyticN
1009The credentials provided were failed to be authenticated by the serverOperationalN
1010RDP ClientActiveX is connecting to a gateway server (Name=Value).AnalyticN
1011RDP ClientActiveX succeeded in connecting to the gateway serverAnalyticN
1012RDP ClientActiveX failed to connect to the gateway server(Error= ErrorCode).AnalyticN
1013RDP ClientActiveX is trying to automatically reconnect to the server (Value).AnalyticN
1014RDP ClientActiveX succeeded in automatically connecting to the serverAnalyticN
1015RDP ClientActiveX failed to automatically connect to the server (Reason= …OperationalN
1016Client has a license to connect to the serverAnalyticN
1017Client does not have a license to connect to the server (Error= ErrorCode).OperationalN
1018RDP ClientActiveX failed to connect to the server (Error = ErrorCode).AnalyticN
1019TraceMessage.AnalyticN
1020RDP ClientActiveX has recorded the following error - ErrorCode.AnalyticN
1021RDP ClientActiveX's gateway transport has recorded the following error - Value.AnalyticN
1022TraceMessage.AnalyticN
1023RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder …AnalyticN
1024RDP ClientActiveX is trying to connect to the server (Value).OperationalY
1025RDP ClientActiveX has connected to the serverOperationalY
1026RDP ClientActiveX has been disconnected (Reason= Value).OperationalY
1027Connected to domain (DomainName) with session SessionId.OperationalN
1028Server supports SSL = TraceMessage.OperationalY
1029Base64(SHA256(UserName)) is = TraceMessage.OperationalY
1030RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.AnalyticN
1031Invalid format error occured when decoding packet of type TraceMessage.OperationalN
1032Component name:ErrorCode, :: ErrorDescription.DebugN
1033Component name:Name, :: CustomLevel, Error code:Value.OperationalN
1034Component name:ErrorCode, :: ErrorDescription.OperationalN
1100The client detected the link latency is Value milliseconds.OperationalN
1101The client detected the bandwidth is Value kbps/second.OperationalN
1102The client has initiated a multi-transport connection to the server Value.OperationalY
1103The client has established a multi-transport connection to the server.OperationalY
1104The client failed to establish the multi-transport connection.OperationalN
1105The multi-transport connection has been disconnected.OperationalY
1106Close event, code = Code.OperationalN
1107Disconnect trace:ComponentName "Message", Error code:ErrorCode.OperationalN
1201The RdClient has been forced exit since cancelling existing workspace job took …OperationalN
1202The user has clicked sign out on the OOB Client ribbon.OperationalN
1203The user has clicked Refresh on the OOB client ribbon.OperationalN
1204The user tried to login into ADAL with a different user name than the one he/she …OperationalN
1205Event: Workspace Event succeeded for Tenant = TenantId , TotalTimeWithoutAdal = …OperationalN
1206Event: Workspace Event failed for Tenant = TenantId.OperationalN
1207RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.AnalyticN
1208Feed discovery succeeded.OperationalN
1209Feed discovery failed.OperationalN
1210Feed cache corruption encountered.OperationalN
1211Consent status updated successfully.OperationalN
1212Consent status update failed.OperationalN
1213The user has clicked view invitations on the OOB client ribbon.OperationalN
1214Base64(SHA256(UserName)) = UserNameHash, TimeZone Bias = TimeZoneBias, TimeZone …OperationalN
1215Refresh Time = refreshTime, Number of feeds = numberOfFeeds.OperationalN
1216ADAL error code = ErrorCode, description = ErrorDescription.OperationalN
1217ADAL token collected successfullyOperationalN
1218ADAL cancelledOperationalN
1227RadcClientType entering stage RadcClientStage.OperationalN
1228RadcClientStage with http event type RadcHttpEvent.OperationalN
1229RadcClientStage with http event type RadcHttpEvent and http status code Code.OperationalN
1230RadcClientStage with http event type RadcHttpEvent failed with xresult Code.OperationalN
1401The server is using version Version of the RDP graphics protocol (client mode: …OperationalY
1402The client is using hardware memory for the frame buffer.OperationalY
1403The client is using software memory for the frame buffer.OperationalY
1404The client encountered an issue while decoding and displaying RDP graphics …OperationalN
1501TraceMessage.AnalyticN
1502TraceMessage.AnalyticN
1503TraceMessage.AnalyticN

Event ID 225: StateTransitionName: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Task
RDPStateTransition
Opcode
Thiseventisraisedduringastatetransition.

Description

StateTransitionName: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

Message #

%1: Transitioned successfully from %3 to %5 in response to %7.

Fields #

NameDescription
StateTransitionName UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString

Event ID 226: StateTransitionName: An error was encountered when transitioning from PreviousStateName to NewStateName in response to EventName (error code Error Code).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Warning
Task
RDPStateTransition
Opcode
Thiseventisraisedduringastatetransition.

Description

StateTransitionName: An error was encountered when transitioning from PreviousStateName to NewStateName in response to EventName (error code Error Code).

Message #

%1: An error was encountered when transitioning from %3 to %5 in response to %7 (error code %8).

Fields #

NameDescription
StateTransitionName UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 226,
    "version": 0,
    "level": 3,
    "task": 104,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-13T18:26:54.989202+00:00",
    "event_record_id": 4,
    "correlation": {
      "ActivityID": "DB2461B3-3531-4655-AE9C-36EB94410000"
    },
    "execution": {
      "process_id": 12488,
      "thread_id": 13944
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "StateTransitionName": "RDPClient_SSL",
    "PreviousState": 2,
    "PreviousStateName": "TsSslStateHandshakeStart",
    "NewState": 10,
    "NewStateName": "TsSslStateDisconnecting",
    "Event": 7,
    "EventName": "TsSslEventStartHandshakeFailed",
    "Error Code": 2147500037
  },
  "message": ""
}

Event ID 227: StateTransitionName: MCS Channel Join Confirmation received: ChannelID = ChannelID, ChannelName = ChannelName.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Task
RDPStateTransition
Opcode
Thiseventisraisedduringastatetransition.

Description

StateTransitionName: MCS Channel Join Confirmation received: ChannelID = ChannelID, ChannelName = ChannelName.

Message #

%1: MCS Channel Join Confirmation received: ChannelID = %2, ChannelName = %3.

Fields #

NameDescription
StateTransitionName UnicodeString
ChannelID UInt32
ChannelName UnicodeString

Event ID 1000: task_0

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Opcode
Info

Fields #

NameDescription
Function UnicodeString
Line UnicodeString
DebugMessage UnicodeString

Event ID 1001: RDP ClientActiveX is trying to connect to the server (Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX is trying to connect to the server (Value).

Message #

RDP ClientActiveX is trying to connect to the server (%2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1002: RDP ClientActiveX has connected to the server

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX has connected to the server.

Message #

RDP ClientActiveX has connected to the server

Event ID 1003: RDP ClientActiveX has been disconnected (Reason= Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

RDP ClientActiveX has been disconnected (Reason= Value).

Message #

RDP ClientActiveX has been disconnected (Reason= %2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1004: Client has logged on to the server (SessionId = Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Client has logged on to the server (SessionId = Value).

Message #

Client has logged on to the server (SessionId = %2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1005: Client failed to logon on to the server (Error = ErrorCode).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Client failed to logon on to the server (Error = ErrorCode).

Message #

Client failed to logon on to the server (Error = %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1006: Client machine has lost network connectivity (Reason= ErrorCode).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

Client machine has lost network connectivity (Reason= ErrorCode).

Message #

Client machine has lost network connectivity (Reason= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1007: DNS failed to resolve the server name (Error= ErrorCode).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringresolvingtheservername

Description

DNS failed to resolve the server name (Error= ErrorCode).

Message #

DNS failed to resolve the server name (Error= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1008: The credentials provided are authenticated by the server

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheauthenticationprocess

Description

The credentials provided are authenticated by the server.

Message #

The credentials provided are authenticated by the server

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1009: The credentials provided were failed to be authenticated by the server

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheauthenticationprocess

Description

The credentials provided were failed to be authenticated by the server.

Message #

The credentials provided were failed to be authenticated by the server

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1010: RDP ClientActiveX is connecting to a gateway server (Name=Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX is connecting to a gateway server (Name=Value).

Message #

RDP ClientActiveX is connecting to a gateway server (%1=%2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1011: RDP ClientActiveX succeeded in connecting to the gateway server

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX succeeded in connecting to the gateway server.

Message #

RDP ClientActiveX succeeded in connecting to the gateway server

Event ID 1012: RDP ClientActiveX failed to connect to the gateway server(Error= ErrorCode).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX failed to connect to the gateway server(Error= ErrorCode).

Message #

RDP ClientActiveX failed to connect to the gateway server(Error= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1013: RDP ClientActiveX is trying to automatically reconnect to the server (Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
AutomaticReconnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

RDP ClientActiveX is trying to automatically reconnect to the server (Value).

Message #

RDP ClientActiveX is trying to automatically reconnect to the server (%2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1014: RDP ClientActiveX succeeded in automatically connecting to the server

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
AutomaticReconnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

RDP ClientActiveX succeeded in automatically connecting to the server.

Message #

RDP ClientActiveX succeeded in automatically connecting to the server

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1015: RDP ClientActiveX failed to automatically connect to the server (Reason= TraceMessage).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
AutomaticReconnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

RDP ClientActiveX failed to automatically connect to the server (Reason= TraceMessage).

Message #

RDP ClientActiveX failed to automatically connect to the server (Reason= %1)

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1016: Client has a license to connect to the server

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedwhiletryingtogetavalidlicense

Description

Client has a license to connect to the server.

Message #

Client has a license to connect to the server

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1017: Client does not have a license to connect to the server (Error= ErrorCode).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedwhiletryingtogetavalidlicense

Description

Client does not have a license to connect to the server (Error= ErrorCode).

Message #

Client does not have a license to connect to the server (Error= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1018: RDP ClientActiveX failed to connect to the server (Error = ErrorCode).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX failed to connect to the server (Error = ErrorCode).

Message #

RDP ClientActiveX failed to connect to the server (Error = %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1019: TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Description

TraceMessage

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1020: RDP ClientActiveX has recorded the following error - ErrorCode.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Description

RDP ClientActiveX has recorded the following error - ErrorCode. Check Details.

Message #

RDP ClientActiveX has recorded the following error - %2. Check Details.

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1021: RDP ClientActiveX's gateway transport has recorded the following error - Value.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX's gateway transport has recorded the following error - Value. Check Details.

Message #

RDP ClientActiveX's gateway transport has recorded the following error - %2. Check Details.

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1022: TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

TraceMessage

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1023: RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder type = Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence

Description

RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder type = Value).

Message #

RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder type = %2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1024: RDP ClientActiveX is trying to connect to the server (Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX is trying to connect to the server (Value).

Message #

RDP ClientActiveX is trying to connect to the server (%2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1024,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:36.580526+00:00",
    "event_record_id": 1,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 11240
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Name": "Server Name",
    "Value": "29A7892D-8743-4A3F-85E3-06FE9D7977B4",
    "CustomLevel": "Info"
  },
  "message": ""
}

Detection Rules #

View all rules referencing this event →

Splunk # view in coverage

  • Windows RDPClient Connection Sequence Events source: This analytic monitors Windows RDP client connection sequence events (EventCode 1024) from the Microsoft-Windows-TerminalServices-RDPClient/Operational log. These events track when RDP ClientActiveX initiates connection attempts to remote…

References #

Event ID 1025: RDP ClientActiveX has connected to the server

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Collection Priority
Recommended (ANSSI)
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX has connected to the server.

Message #

RDP ClientActiveX has connected to the server

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:37.058263+00:00",
    "event_record_id": 4,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 5172
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1026: RDP ClientActiveX has been disconnected (Reason= Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

RDP ClientActiveX has been disconnected (Reason= Value).

Message #

RDP ClientActiveX has been disconnected (Reason= %2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "{28AA95BB-D444-4719-A36F-40462168127E}",
    "event_source_name": "",
    "event_id": 1026,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2026-04-16T22:43:34.7715095+00:00",
    "event_record_id": 15,
    "correlation": {
      "ActivityID": "{CA27B9FB-05E9-46ED-A43C-B3EB30180000}"
    },
    "execution": {
      "process_id": 17100,
      "thread_id": 17348
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Name": "Disconnect Reason",
    "Value": "1",
    "CustomLevel": "Info"
  },
  "message": "RDP ClientActiveX has been disconnected (Reason= 1)"
}

Event ID 1027: Connected to domain (DomainName) with session SessionId.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Connected to domain (DomainName) with session SessionId.

Message #

Connected to domain (%1) with session %2.

Fields #

NameDescription
DomainName UnicodeString
SessionId UInt32

Event ID 1028: Server supports SSL = TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Server supports SSL = TraceMessage.

Message #

Server supports SSL = %1

Fields #

NameDescription
TraceMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1028,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:36.991587+00:00",
    "event_record_id": 2,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 5172
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "TraceMessage": "not supported"
  },
  "message": ""
}

Event ID 1029: Base64(SHA256(UserName)) is = TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Base64(SHA256(UserName)) is = TraceMessage.

Message #

Base64(SHA256(UserName)) is = %1

Fields #

NameDescription
TraceMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1029,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:36.992493+00:00",
    "event_record_id": 3,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 11240
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "TraceMessage": "-"
  },
  "message": ""
}

Event ID 1030: RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence

Description

RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

Message #

RDP Client build %1 %2 %3 %4 %5

Fields #

NameDescription
BuildBranch UnicodeString
BuildDate UnicodeString
BuildTime UnicodeString
BuildVersion UnicodeString
ArchAndFlavour UnicodeString

Event ID 1031: Invalid format error occured when decoding packet of type TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

Invalid format error occured when decoding packet of type TraceMessage.

Message #

Invalid format error occured when decoding packet of type %1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1032: Component name:ErrorCode, :: ErrorDescription.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Task
General
Opcode
Thisisagenericeventthatmayberaisedbytheclient.

Description

Component name:ErrorCode, :: ErrorDescription.

Message #

Component name:%1, :: %2

Fields #

NameDescription
ErrorCode UnicodeString
ErrorDescription UnicodeString

Event ID 1033: Component name:Name, :: CustomLevel, Error code:Value.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
General
Opcode
Thisisagenericerrorthatmaybesignaledbytheclient.

Description

Component name:Name, :: CustomLevel, Error code:Value.

Message #

Component name:%1, :: %2, Error code:%3

Fields #

NameDescription
Name UnicodeString
CustomLevel UnicodeString
Value HexInt32

Event ID 1034: Component name:ErrorCode, :: ErrorDescription.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
General
Opcode
Thisisagenericeventthatmayberaisedbytheclient.

Description

Component name:ErrorCode, :: ErrorDescription.

Message #

Component name:%1, :: %2

Fields #

NameDescription
ErrorCode UnicodeString
ErrorDescription UnicodeString

Event ID 1100: The client detected the link latency is Value milliseconds.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client detected the link latency is Value milliseconds.

Message #

The client detected the link latency is %2 milliseconds.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1101: The client detected the bandwidth is Value kbps/second.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client detected the bandwidth is Value kbps/second.

Message #

The client detected the bandwidth is %2 kbps/second.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1102: The client has initiated a multi-transport connection to the server Value.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client has initiated a multi-transport connection to the server Value.

Message #

The client has initiated a multi-transport connection to the server %2.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "{28AA95BB-D444-4719-A36F-40462168127E}",
    "event_source_name": "",
    "event_id": 1102,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-04-16T21:56:41.7226635+00:00",
    "event_record_id": 9,
    "correlation": {
      "ActivityID": "{CA27B9FB-05E9-46ED-A43C-B3EB30180000}"
    },
    "execution": {
      "process_id": 17100,
      "thread_id": 17460
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Name": "ServerAddress",
    "Value": "10.2.10.91",
    "CustomLevel": "Info"
  },
  "message": "The client has initiated a multi-transport connection to the server 10.2.10.91."
}

Event ID 1103: The client has established a multi-transport connection to the server.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client has established a multi-transport connection to the server.

Message #

The client has established a multi-transport connection to the server.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "{28AA95BB-D444-4719-A36F-40462168127E}",
    "event_source_name": "",
    "event_id": 1103,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-04-16T21:56:41.9856707+00:00",
    "event_record_id": 11,
    "correlation": {
      "ActivityID": "{CA27B9FB-05E9-46ED-A43C-B3EB30180000}"
    },
    "execution": {
      "process_id": 17100,
      "thread_id": 17168
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": "The client has established a multi-transport connection to the server."
}

Event ID 1104: The client failed to establish the multi-transport connection.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client failed to establish the multi-transport connection.

Message #

The client failed to establish the multi-transport connection.

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1105: The multi-transport connection has been disconnected.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The multi-transport connection has been disconnected.

Message #

The multi-transport connection has been disconnected.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1105,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-13T18:26:54.989606+00:00",
    "event_record_id": 5,
    "correlation": {
      "ActivityID": "DB2461B3-3531-4655-AE9C-36EB94410000"
    },
    "execution": {
      "process_id": 12488,
      "thread_id": 13944
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1106: Close event, code = Code.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedwhenthereisacloseoperationwhichwillteardowntheconnection.

Description

Close event, code = Code.

Message #

Close event, code = %1.

Fields #

NameDescription
Code UInt32

Event ID 1107: Disconnect trace:ComponentName "Message", Error code:ErrorCode.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
General
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

Disconnect trace:ComponentName "Message", Error code:ErrorCode.

Message #

Disconnect trace:%1 "%2", Error code:%3

Fields #

NameDescription
ComponentName UnicodeString
Message UnicodeString
ErrorCode UInt32

Event ID 1201: The RdClient has been forced exit since cancelling existing workspace job took too long.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheclienthasnotbeenshutdowncleanly.

Description

The RdClient has been forced exit since cancelling existing workspace job took too long.

Message #

The RdClient has been forced exit since cancelling existing workspace job took too long.

Event ID 1202: The user has clicked sign out on the OOB Client ribbon.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhentheusertriestosignoutfromtheOOBclient.

Description

The user has clicked sign out on the OOB Client ribbon.

Message #

The user has clicked sign out on the OOB Client ribbon.

Event ID 1203: The user has clicked Refresh on the OOB client ribbon.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheusermanuallytriestodofeedrefresh.

Description

The user has clicked Refresh on the OOB client ribbon.

Message #

The user has clicked Refresh on the OOB client ribbon.

Event ID 1204: The user tried to login into ADAL with a different user name than the one he/she subscribed to initially.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhentheusertriestologininADALpageusingdifferentusername.

Description

The user tried to login into ADAL with a different user name than the one he/she subscribed to initially.

Message #

The user tried to login into ADAL with a different user name than the one he/she subscribed to initially.

Event ID 1205: Event: Workspace Event succeeded for Tenant = TenantId , TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenaworkspaceeventlikesubscribe/updatesucceeded.

Description

Event: Workspace Event succeeded for Tenant = TenantId , TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms. NumberOfResources = ErrorCode.

Message #

%1: Workspace Event succeeded for Tenant = %2 , TotalTimeWithoutAdal = %3 ms, AdalTime = %4 ms. NumberOfResources = %5

Fields #

NameDescription
Event UnicodeString
TenantId UnicodeString
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1206: Event: Workspace Event failed for Tenant = TenantId.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenaworkspaceeventlikesubscribe/updatefailed!

Description

Event: Workspace Event failed for Tenant = TenantId. , TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms. (Error code ErrorCode).

Message #

%1: Workspace Event failed for Tenant = %2. , TotalTimeWithoutAdal = %3 ms, AdalTime = %4 ms. (Error code %5)

Fields #

NameDescription
Event UnicodeString
TenantId UnicodeString
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1207: RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
RdClientRADCworkspace

Description

RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

Message #

RDP Client build %1 %2 %3 %4 %5

Fields #

NameDescription
BuildBranch UnicodeString
BuildDate UnicodeString
BuildTime UnicodeString
BuildVersion UnicodeString
ArchAndFlavour UnicodeString

Event ID 1208: Feed discovery succeeded.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenfeeddiscoverysucceeds

Description

Feed discovery succeeded. TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms, NumberOfFeeds = NumberOfFeeds.

Message #

Feed discovery succeeded. TotalTimeWithoutAdal = %1 ms, AdalTime = %2 ms, NumberOfFeeds = %3

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32
NumberOfFeeds UInt32

Event ID 1209: Feed discovery failed.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenfeeddiscoveryfailed!

Description

Feed discovery failed. TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms. (Error code = ErrorCode).

Message #

Feed discovery failed. TotalTimeWithoutAdal = %1 ms, AdalTime = %2 ms. (Error code = %3)

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1210: Feed cache corruption encountered.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenthefeedcacheontheclientlocalmachineismissingiconsorRdpfilesduetocachecorruption!

Description

Feed cache corruption encountered. Tenant = TenantId, ResourceId = ResourceIndex, ResourceType = ResourceType, (Error code ErrorCode).

Message #

Feed cache corruption encountered. Tenant = %1, ResourceId = %2, ResourceType = %3, (Error code %4).

Fields #

NameDescription
TenantId UnicodeString
ResourceIndex UInt32
ResourceType UnicodeString
ErrorCode UInt32

Event ID 1211: Consent status updated successfully.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenuserhassuccessfullyupdatedtheconsentstatusonserverside

Description

Consent status updated successfully. TotalTimeWithoutAdal = TotalTimeWithoutAdal, AdalTime = AdalTime.

Message #

Consent status updated successfully. TotalTimeWithoutAdal =  %1, AdalTime = %2.

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32

Event ID 1212: Consent status update failed.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenuserisunabletoupdatetheconsentstatusonserver!

Description

Consent status update failed. TotalTimeWithoutAdal = TotalTimeWithoutAdal, AdalTime = AdalTime. (Error code ErrorCode).

Message #

Consent status update failed. TotalTimeWithoutAdal =  %1, AdalTime = %2. (Error code %3)

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1213: The user has clicked view invitations on the OOB client ribbon.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheusermanuallyclickstheviewinvitationsbutton.

Description

The user has clicked view invitations on the OOB client ribbon.

Message #

The user has clicked view invitations on the OOB client ribbon.

Event ID 1214: Base64(SHA256(UserName)) = UserNameHash, TimeZone Bias = TimeZoneBias, TimeZone Name = TimeZoneName.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheuserstartsanewcycleoffeeddiscovery.WelogthehashedUPNandtimezoneinformationhere

Description

Base64(SHA256(UserName)) = UserNameHash, TimeZone Bias = TimeZoneBias, TimeZone Name = TimeZoneName.

Message #

Base64(SHA256(UserName)) = %1, TimeZone Bias = %2, TimeZone Name = %3.

Fields #

NameDescription
UserNameHash UnicodeString
TimeZoneBias Int32
TimeZoneName UnicodeString

Event ID 1215: Refresh Time = refreshTime, Number of feeds = numberOfFeeds.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenallthefeedsoftheuserhavebeensubscribedorupdatedcompletely.Welogtheoveralltimeittooktodownloadallfeedsinparallel.

Description

Refresh Time = refreshTime, Number of feeds = numberOfFeeds.

Message #

Refresh Time = %1, Number of feeds = %2.

Fields #

NameDescription
refreshTime UInt32
numberOfFeeds UInt32

Event ID 1216: ADAL error code = ErrorCode, description = ErrorDescription.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenthereiserrorinacquiringADALtoken.

Description

ADAL error code = ErrorCode, description = ErrorDescription.

Message #

ADAL error code = %1, description = %2

Fields #

NameDescription
ErrorCode UnicodeString
ErrorDescription UnicodeString

Event ID 1217: ADAL token collected successfully

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenADALauthenticationtokenissuccessfullycreated.

Description

ADAL token collected successfully.

Message #

ADAL token collected successfully

Event ID 1218: ADAL cancelled

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenADALauthenticationiscancelled.

Description

ADAL cancelled.

Message #

ADAL cancelled

Event ID 1227: RadcClientType entering stage RadcClientStage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientType entering stage RadcClientStage.

Message #

%1 entering stage %2

Fields #

NameDescription
RadcClientType UnicodeString
RadcClientStage UnicodeString

Event ID 1228: RadcClientStage with http event type RadcHttpEvent.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientStage with http event type RadcHttpEvent.

Message #

%1 with http event type %2

Fields #

NameDescription
RadcClientStage UnicodeString
RadcHttpEvent UnicodeString

Event ID 1229: RadcClientStage with http event type RadcHttpEvent and http status code Code.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientStage with http event type RadcHttpEvent and http status code Code.

Message #

%1 with http event type %2 and http status code %3

Fields #

NameDescription
RadcClientStage UnicodeString
RadcHttpEvent UnicodeString
Code UInt32

Event ID 1230: RadcClientStage with http event type RadcHttpEvent failed with xresult Code.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientStage with http event type RadcHttpEvent failed with xresult Code.

Message #

%1 with http event type %2 failed with xresult %3

Fields #

NameDescription
RadcClientStage UnicodeString
RadcHttpEvent UnicodeString
Code UInt32

Event ID 1401: The server is using version Version of the RDP graphics protocol (client mode: ClientMode, AVC available: AvcEnabled).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedwhenprotocolcapsarereceivedfromtheserver.Welogtheversionselected,andtheclientmodeandAVCcapability.

Description

The server is using version Version of the RDP graphics protocol (client mode: ClientMode, AVC available: AvcEnabled).

Message #

The server is using version %1 of the RDP graphics protocol (client mode: %2, AVC available: %3).

Fields #

NameDescription
Version HexInt32
ClientMode UInt32
AvcEnabled UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1401,
    "version": 0,
    "level": 4,
    "task": 106,
    "opcode": 36,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:37.635292+00:00",
    "event_record_id": 6,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Version": "0x80004",
    "ClientMode": 0,
    "AvcEnabled": 0
  },
  "message": ""
}

Event ID 1402: The client is using hardware memory for the frame buffer.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedwhenprotocolcapsarereceivedfromtheserver.Welogthathardwareresourcesarebeingused.

Description

The client is using hardware memory for the frame buffer.

Message #

The client is using hardware memory for the frame buffer.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "{28AA95BB-D444-4719-A36F-40462168127E}",
    "event_source_name": "",
    "event_id": 1402,
    "version": 0,
    "level": 4,
    "task": 106,
    "opcode": 37,
    "keywords": 4611686018427387904,
    "time_created": "2026-04-16T21:56:42.1393173+00:00",
    "event_record_id": 12,
    "correlation": {
      "ActivityID": "{CA27B9FB-05E9-46ED-A43C-B3EB30180000}"
    },
    "execution": {
      "process_id": 17100,
      "thread_id": 14148
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": "The client is using hardware memory for the frame buffer."
}

Event ID 1403: The client is using software memory for the frame buffer.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedwhenprotocolcapsarereceivedfromtheserver.Welogthathardwareresourcesarenotbeingused.

Description

The client is using software memory for the frame buffer.

Message #

The client is using software memory for the frame buffer.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1403,
    "version": 0,
    "level": 4,
    "task": 106,
    "opcode": 38,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:37.464424+00:00",
    "event_record_id": 5,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1404: The client encountered an issue while decoding and displaying RDP graphics (component: Component, function: Function, error code: ErrorCode).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedifapipelineerrorisencounteredduringexecution.Welogthefaultingcomponent,function,anderrorcode.

Description

The client encountered an issue while decoding and displaying RDP graphics (component: Component, function: Function, error code: ErrorCode).

Message #

The client encountered an issue while decoding and displaying RDP graphics (component: %1, function: %2, error code: %3)

Fields #

NameDescription
Component UnicodeString
Function UInt32
ErrorCode UInt32

Event ID 1501: TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Description

TraceMessage

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1502: TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Description

TraceMessage

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1503: TraceMessage.

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Description

TraceMessage

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 28aa95bb-d444-4719-a36f-40462168127e

Defined in mstscax.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3915, captured 2026-06-02

Downloads