Microsoft-Windows-TerminalServices-LocalSessionManager

47 events across 3 channels

EventTitleChannelSample
2message.DebugN
3message.DebugN
4message.DebugN
5message.DebugN
6message.DebugN
7message.DebugN
8message.DebugN
9message.DebugN
10LogonProcessingStartAnalyticN
11LogonProcessingStopAnalyticN
16Local Multi-User session manager failed to start.OperationalN
17Remote Desktop Service start failed.OperationalY
18Remote Desktop Service is shutdown for unknown reason.OperationalN
19Registering with Service Control Manager to monitor Remote Desktop Service …OperationalY
20Attempt to send messageName message to Windows video subsystem failed.OperationalN
21Remote Desktop Services: Session logon succeeded.OperationalY
22Remote Desktop Services: Shell start notification received.OperationalY
23Remote Desktop Services: Session logoff succeeded.OperationalY
24Remote Desktop Services: Session has been disconnected.OperationalY
25Remote Desktop Services: Session reconnection succeeded.OperationalY
32Plugin EventXML.messageName has been successfully initialized.OperationalY
33Plugin messageName failed to initialize, error code errorCode.OperationalN
34Remote Desktop Services is not accepting logons because setup is running.OperationalY
35The client process ID Param1 could not complete the session change notification …OperationalN
36An error occurred when transitioning from StateName in response to EventName.OperationalY
37Invalid state transition from StateName in response to EventName.OperationalN
38Transitioned successfully from PreviousStateName to NewStateName in response to …DebugN
39Session EventXML.TargetSession has been disconnected by session EventXML.Source.OperationalY
40Session 5 has been disconnected, reason code 12OperationalY
41Begin session arbitration.OperationalY
42End session arbitration.OperationalY
43Windows Subsystem has taken too long to process Connect event for session …OperationalN
44Windows Subsystem has taken too long to process Disconnect event for session …OperationalN
45Windows Subsystem has taken too long to process Terminate event for session …OperationalN
48Remote Connection Manager has taken too long to process logon message for …OperationalN
49Remote Connection Manager has taken too long to prepare for session arbitration …OperationalN
50Remote Connection Manager has taken too long to process begin-connect-message …OperationalN
51Remote Connection Manager has taken too long to process end-connect-message for …OperationalN
52Remote Connection Manager has taken too long to process begin-disconnect-message …OperationalN
53Remote Connection Manager has taken too long to process end-disconnect-message …OperationalN
54Local multi-user session manager received system shutdown messageOperationalY
55Remote Desktop Service has taken too long to start upOperationalN
56Remote Desktop Service has taken too long to shutdownOperationalN
57Session SessionID has started with Initial Command Process ID InitCmdPid and …DebugN
58Session SessionID has started with Initial Command Process ID InitCmdPid …DebugN
59Function from CallerImageName( #0xSessionId/0xClientProcessId ).OperationalY
60Glass session SessionID has been reconnected to a remote protocol, this session …OperationalN

Event ID 2: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 3: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 4: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 5: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 6: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 7: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 8: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 9: message.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

message

Message #

%1

Fields #

NameDescription
message AnsiString

Event ID 10: LogonProcessingStart

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Analytic
Task
LogonProcessing
Opcode
Start

Event ID 11: LogonProcessingStop

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Analytic
Task
LogonProcessing
Opcode
Stop

Event ID 16: Local Multi-User session manager failed to start.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Local Multi-User session manager failed to start. The relevant status code was Param1.

Message #

Local Multi-User session manager failed to start. The relevant status code was %1.

Fields #

NameDescription
Param1 HexInt32

Event ID 17: Remote Desktop Service start failed.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)

Description

Remote Desktop Service start failed. The relevant status code was EventXML.Param1.

Message #

Remote Desktop Service start failed. The relevant status code was %1.

Fields #

NameDescription
Param1 HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "5D896912-022D-40AA-A3A8-4FA5515C76D7",
    "event_source_name": "",
    "event_id": 17,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-13T18:28:58.767431+00:00",
    "event_record_id": 199,
    "correlation": {},
    "execution": {
      "process_id": 1216,
      "thread_id": 1252
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "Param1": "0x80010108"
    }
  },
  "message": ""
}

Event ID 18: Remote Desktop Service is shutdown for unknown reason.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Desktop Service is shutdown for unknown reason. Will recover in one minute.

Message #

Remote Desktop Service is shutdown for unknown reason. Will recover in one minute.

Event ID 19: Registering with Service Control Manager to monitor Remote Desktop Service status failed with Param1, retry in ten minutes.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Registering with Service Control Manager to monitor Remote Desktop Service status failed with Param1, retry in ten minutes.

Message #

Registering with Service Control Manager to monitor Remote Desktop Service status failed with %1, retry in ten minutes.

Fields #

NameDescription
Param1 HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "event_id": 19,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-03-17T19:22:46.0368215+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational"
  },
  "event_data": {
    "Param1": "0x8007045b"
  }
}

Event ID 20: Attempt to send messageName message to Windows video subsystem failed.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Attempt to send messageName message to Windows video subsystem failed. The relevant status code was errorCode.

Message #

Attempt to send %1 message to Windows video subsystem failed. The relevant status code was %2.

Fields #

NameDescription
messageName UnicodeString
errorCode HexInt32

Event ID 21: Remote Desktop Services: Session logon succeeded.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)

Description

Remote Desktop Services: Session logon succeeded.

Message #

Remote Desktop Services: Session logon succeeded:

User: %1
Session ID: %2
Source Network Address: %3

Fields #

NameDescriptionRules
EventXML.User
EventXML.SessionID
EventXML.Address1 detection rule
User
SessionID
Address1 detection rule

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "{5D896912-022D-40AA-A3A8-4FA5515C76D7}",
    "event_source_name": "",
    "event_id": 21,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-05-29T16:33:56.6854498+00:00",
    "event_record_id": 109,
    "correlation": {
      "ActivityID": "{61A55000-55E5-1017-0000-000000000000}"
    },
    "execution": {
      "process_id": 1056,
      "thread_id": 5280
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "User": "cell-a\\domainadmin",
      "SessionID": "1",
      "Address": "LOCAL"
    }
  },
  "message": "Remote Desktop Services: Session logon succeeded:\r\n\r\nUser: cell-a\\domainadmin\r\nSession ID: 1\r\nSource Network Address: LOCAL"
}

Detection Patterns #

Community Notes #

Remote desktop services shell start. Occurs when a user successfully establishes a session and the shell starts, confirming a successful interactive logon.

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

References #

Event ID 22: Remote Desktop Services: Shell start notification received.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)

Description

Remote Desktop Services: Shell start notification received.

Message #

Remote Desktop Services: Shell start notification received:

User: %1
Session ID: %2
Source Network Address: %3

Fields #

NameDescription
EventXML.User
EventXML.SessionID
EventXML.Address
User
SessionID
Address

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "{5D896912-022D-40AA-A3A8-4FA5515C76D7}",
    "event_source_name": "",
    "event_id": 22,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-05-29T16:33:57.4792419+00:00",
    "event_record_id": 110,
    "correlation": {
      "ActivityID": "{61A55000-55E5-1017-0000-000000000000}"
    },
    "execution": {
      "process_id": 1056,
      "thread_id": 5276
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "User": "cell-a\\domainadmin",
      "SessionID": "1",
      "Address": "LOCAL"
    }
  },
  "message": "Remote Desktop Services: Shell start notification received:\r\n\r\nUser: cell-a\\domainadmin\r\nSession ID: 1\r\nSource Network Address: LOCAL"
}

References #

Event ID 23: Remote Desktop Services: Session logoff succeeded.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)

Description

Remote Desktop Services: Session logoff succeeded.

Message #

Remote Desktop Services: Session logoff succeeded:

User: %1
Session ID: %2

Fields #

NameDescription
EventXML.User
EventXML.SessionID
User
SessionID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "{5D896912-022D-40AA-A3A8-4FA5515C76D7}",
    "event_source_name": "",
    "event_id": 23,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-06-13T05:22:33.7568572+00:00",
    "event_record_id": 112,
    "correlation": {
      "ActivityID": "{61A55000-55E5-1017-0000-000000000000}"
    },
    "execution": {
      "process_id": 1048,
      "thread_id": 7996
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "User": "cell-c\\domainadmin",
      "SessionID": "1"
    }
  },
  "message": "Remote Desktop Services: Session logoff succeeded:\r\n\r\nUser: cell-c\\domainadmin\r\nSession ID: 1"
}

References #

Event ID 24: Remote Desktop Services: Session has been disconnected.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)

Description

Remote Desktop Services: Session has been disconnected.

Message #

Remote Desktop Services: Session has been disconnected:

User: %1
Session ID: %2
Source Network Address: %3

Fields #

NameDescription
User
SessionID
Address

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "5D896912-022D-40AA-A3A8-4FA5515C76D7",
    "event_source_name": "",
    "event_id": 24,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2024-11-22T22:49:17.027344+00:00",
    "event_record_id": 2333,
    "correlation": {
      "ActivityID": "F42007FF-53B7-440F-9169-DEE2D7900000"
    },
    "execution": {
      "process_id": 896,
      "thread_id": 2060
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "EC2AMAZ-3NFFVNI",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "User": "EC2AMAZ-3NFFVNI\\samurai",
      "SessionID": 5,
      "Address": "198.51.100.2"
    }
  },
  "message": "Remote Desktop Services: Session has been disconnected:\n\nUser: EC2AMAZ-3NFFVNI\\samurai\nSession ID: 5\nSource Network Address: 198.51.100.2"
}

Detection Patterns #

References #

Event ID 25: Remote Desktop Services: Session reconnection succeeded.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)

Description

Remote Desktop Services: Session reconnection succeeded.

Message #

Remote Desktop Services: Session reconnection succeeded:

User: %1
Session ID: %2
Source Network Address: %3

Fields #

NameDescription
User
SessionID
Address

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "5D896912-022D-40AA-A3A8-4FA5515C76D7",
    "event_source_name": "",
    "event_id": 25,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2024-11-22T22:48:31.312554+00:00",
    "event_record_id": 2323,
    "correlation": {
      "ActivityID": "F4209548-02F6-4100-AC4D-324EFFDE0000"
    },
    "execution": {
      "process_id": 896,
      "thread_id": 4048
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "EC2AMAZ-3NFFVNI",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "User": "EC2AMAZ-3NFFVNI\\samurai",
      "SessionID": 4,
      "Address": "198.51.100.2"
    }
  },
  "message": "Remote Desktop Services: Session reconnection succeeded:\n\nUser: EC2AMAZ-3NFFVNI\\samurai\nSession ID: 4\nSource Network Address: 198.51.100.2"
}

Detection Patterns #

References #

Event ID 32: Plugin EventXML.messageName has been successfully initialized.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Plugin EventXML.messageName has been successfully initialized.

Message #

Plugin %1 has been successfully initialized

Fields #

NameDescription
EventXML.messageName
messageName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "{5D896912-022D-40AA-A3A8-4FA5515C76D7}",
    "event_source_name": "",
    "event_id": 32,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-05-29T16:32:52.7785637+00:00",
    "event_record_id": 106,
    "correlation": {},
    "execution": {
      "process_id": 1056,
      "thread_id": 1068
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "messageName": "RDSAppXPlugin"
    }
  },
  "message": "Plugin RDSAppXPlugin has been successfully initialized"
}

Event ID 33: Plugin messageName failed to initialize, error code errorCode.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Plugin messageName failed to initialize, error code errorCode.

Message #

Plugin %1 failed to initialize, error code %2

Fields #

NameDescription
messageName UnicodeString
errorCode HexInt32

Event ID 34: Remote Desktop Services is not accepting logons because setup is running.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Remote Desktop Services is not accepting logons because setup is running.

Message #

Remote Desktop Services is not accepting logons because setup is running.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "5D896912-022D-40AA-A3A8-4FA5515C76D7",
    "event_source_name": "",
    "event_id": 34,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2023-11-06T06:25:36.031054+00:00",
    "event_record_id": 106,
    "correlation": {},
    "execution": {
      "process_id": 500,
      "thread_id": 828
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 35: The client process ID Param1 could not complete the session change notification event sent by the Remote Desktop service.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The client process ID Param1 could not complete the session change notification event sent by the Remote Desktop service. The Remote Desktop service will not send any more session change notifications.

Message #

The client process ID %1 could not complete the session change notification event sent by the Remote Desktop service. The Remote Desktop service will not send any more session change notifications.

Fields #

NameDescription
Param1 HexInt32

Event ID 36: An error occurred when transitioning from StateName in response to EventName.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)

Description

An error occurred when transitioning from StateName in response to EventName. (ErrorCode ErrorCode).

Message #

An error occurred when transitioning from %3 in response to %5. (ErrorCode %6)

Fields #

NameDescription
SessionId UInt32
State UInt32
StateName UnicodeString
Event UInt32
EventName UnicodeString
ErrorCode HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "5D896912-022D-40AA-A3A8-4FA5515C76D7",
    "event_source_name": "",
    "event_id": 36,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-11T03:44:33.193581+00:00",
    "event_record_id": 292,
    "correlation": {
      "ActivityID": "F420E753-C56A-42F2-970E-8E110D740000"
    },
    "execution": {
      "process_id": 1296,
      "thread_id": 2560
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SessionId": 4294967295,
    "State": 0,
    "StateName": "Initialized",
    "Event": 1,
    "EventName": "EvCreated",
    "ErrorCode": "0xd00002fe"
  },
  "message": ""
}

Event ID 37: Invalid state transition from StateName in response to EventName.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Invalid state transition from StateName in response to EventName. (ErrorCode ErrorCode).

Message #

Invalid state transition from %3 in response to %5. (ErrorCode %6)

Fields #

NameDescription
SessionId UInt32
State UInt32
StateName UnicodeString
Event UInt32
EventName UnicodeString
ErrorCode HexInt32

Event ID 38: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

Message #

Transitioned successfully from %3 to %5 in response to %7.

Fields #

NameDescription
SessionId UInt32
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString

Event ID 39: Session EventXML.TargetSession has been disconnected by session EventXML.Source.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Session EventXML.TargetSession has been disconnected by session EventXML.Source.

Message #

Session %1 has been disconnected by session %2

Fields #

NameDescription
TargetSession UInt32
Source UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "5D896912-022D-40AA-A3A8-4FA5515C76D7",
    "event_source_name": "",
    "event_id": 39,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-03-09T00:30:16.216244+00:00",
    "event_record_id": 187,
    "correlation": {
      "ActivityID": "24F57002-F5E4-489C-B423-8C6CF136BD9B"
    },
    "execution": {
      "process_id": 1288,
      "thread_id": 3064
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "TargetSession": 1,
      "Source": 1
    }
  },
  "message": ""
}

Event ID 40: Session 5 has been disconnected, reason code 12

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Session has been disconnected, reason code.

Message #

Session %1 has been disconnected, reason code %2

Fields #

NameDescription
Session
Reason

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "5D896912-022D-40AA-A3A8-4FA5515C76D7",
    "event_source_name": "",
    "event_id": 40,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2024-11-22T22:49:16.916898+00:00",
    "event_record_id": 2332,
    "correlation": {
      "ActivityID": "F42007FF-53B7-440F-9169-DEE2D7900000"
    },
    "execution": {
      "process_id": 896,
      "thread_id": 2060
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "EC2AMAZ-3NFFVNI",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "Session": 5,
      "Reason": 12
    }
  },
  "message": "Session 5 has been disconnected, reason code 12"
}

References #

Event ID 41: Begin session arbitration.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Begin session arbitration.

Message #

Begin session arbitration:

User: %1
Session ID: %2

Fields #

NameDescription
EventXML.User
EventXML.SessionID
User
SessionID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "{5D896912-022D-40AA-A3A8-4FA5515C76D7}",
    "event_source_name": "",
    "event_id": 41,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-05-29T16:33:48.1776171+00:00",
    "event_record_id": 107,
    "correlation": {
      "ActivityID": "{61A55000-55E5-1017-0000-000000000000}"
    },
    "execution": {
      "process_id": 1056,
      "thread_id": 5280
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "User": "cell-a\\domainadmin",
      "SessionID": "1"
    }
  },
  "message": "Begin session arbitration:\r\n\r\nUser: cell-a\\domainadmin\r\nSession ID: 1"
}

Event ID 42: End session arbitration.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

End session arbitration.

Message #

End session arbitration:

User: %1
Session ID: %2

Fields #

NameDescription
EventXML.User
EventXML.SessionID
User
SessionID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "{5D896912-022D-40AA-A3A8-4FA5515C76D7}",
    "event_source_name": "",
    "event_id": 42,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-05-29T16:33:48.1836886+00:00",
    "event_record_id": 108,
    "correlation": {
      "ActivityID": "{61A55000-55E5-1017-0000-000000000000}"
    },
    "execution": {
      "process_id": 1056,
      "thread_id": 5280
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventXML": {
      "User": "cell-a\\domainadmin",
      "SessionID": "1"
    }
  },
  "message": "End session arbitration:\r\n\r\nUser: cell-a\\domainadmin\r\nSession ID: 1"
}

Event ID 43: Windows Subsystem has taken too long to process Connect event for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Windows Subsystem has taken too long to process Connect event for session Session.

Message #

Windows Subsystem has taken too long to process Connect event for session %1

Fields #

NameDescription
Session UInt32

Event ID 44: Windows Subsystem has taken too long to process Disconnect event for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Windows Subsystem has taken too long to process Disconnect event for session Session.

Message #

Windows Subsystem has taken too long to process Disconnect event for session %1

Fields #

NameDescription
Session UInt32

Event ID 45: Windows Subsystem has taken too long to process Terminate event for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Windows Subsystem has taken too long to process Terminate event for session Session.

Message #

Windows Subsystem has taken too long to process Terminate event for session %1

Fields #

NameDescription
Session UInt32

Event ID 48: Remote Connection Manager has taken too long to process logon message for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Connection Manager has taken too long to process logon message for session Session.

Message #

Remote Connection Manager has taken too long to process logon message for session %1

Fields #

NameDescription
Session UInt32

Event ID 49: Remote Connection Manager has taken too long to prepare for session arbitration for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Connection Manager has taken too long to prepare for session arbitration for session Session.

Message #

Remote Connection Manager has taken too long to prepare for session arbitration for session %1

Fields #

NameDescription
Session UInt32

Event ID 50: Remote Connection Manager has taken too long to process begin-connect-message for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Connection Manager has taken too long to process begin-connect-message for session Session.

Message #

Remote Connection Manager has taken too long to process begin-connect-message for session %1

Fields #

NameDescription
Session UInt32

Event ID 51: Remote Connection Manager has taken too long to process end-connect-message for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Connection Manager has taken too long to process end-connect-message for session Session.

Message #

Remote Connection Manager has taken too long to process end-connect-message for session %1

Fields #

NameDescription
Session UInt32

Event ID 52: Remote Connection Manager has taken too long to process begin-disconnect-message for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Connection Manager has taken too long to process begin-disconnect-message for session Session.

Message #

Remote Connection Manager has taken too long to process begin-disconnect-message for session %1

Fields #

NameDescription
Session UInt32

Event ID 53: Remote Connection Manager has taken too long to process end-disconnect-message for session Session.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Connection Manager has taken too long to process end-disconnect-message for session Session.

Message #

Remote Connection Manager has taken too long to process end-disconnect-message for session %1

Fields #

NameDescription
Session UInt32

Event ID 54: Local multi-user session manager received system shutdown message

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Local multi-user session manager received system shutdown message.

Message #

Local multi-user session manager received system shutdown message

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "guid": "{5D896912-022D-40AA-A3A8-4FA5515C76D7}",
    "event_source_name": "",
    "event_id": 54,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 1152921504606846976,
    "time_created": "2026-06-13T05:22:31.8771663+00:00",
    "event_record_id": 111,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 7996
    },
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Local multi-user session manager received system shutdown message"
}

Event ID 55: Remote Desktop Service has taken too long to start up

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Desktop Service has taken too long to start up.

Message #

Remote Desktop Service has taken too long to start up

Event ID 56: Remote Desktop Service has taken too long to shutdown

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Remote Desktop Service has taken too long to shutdown.

Message #

Remote Desktop Service has taken too long to shutdown

Event ID 57: Session SessionID has started with Initial Command Process ID InitCmdPid and Windows Subsystem Process ID Win32kPid.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

Session SessionID has started with Initial Command Process ID InitCmdPid and Windows Subsystem Process ID Win32kPid.

Message #

Session %1 has started with Initial Command Process ID %2 and Windows Subsystem Process ID %3

Fields #

NameDescription
SessionID UInt32
InitCmdPid UInt32
Win32kPid UInt32

Event ID 58: Session SessionID has started with Initial Command Process ID InitCmdPid (InitCmdName) and Windows Subsystem Process ID Win32kPid.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Debug

Description

Session SessionID has started with Initial Command Process ID InitCmdPid (InitCmdName) and Windows Subsystem Process ID Win32kPid.

Message #

Session %1 has started with Initial Command Process ID %2 (%4) and Windows Subsystem Process ID %3

Fields #

NameDescription
SessionID UInt32
InitCmdPid UInt32
Win32kPid UInt32
InitCmdName UnicodeString

Event ID 59: Function from CallerImageName( #0xSessionId/0xClientProcessId ).

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Function from CallerImageName( #0xSessionId/0xClientProcessId ).

Message #

%1 from %2( #0x%3/0x%4 )

Fields #

NameDescription
Function AnsiString
CallerImageName UnicodeString
SessionId UInt32
ClientProcessId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-LocalSessionManager",
    "event_id": 59,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-28T02:27:38.2994946+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-TerminalServices-LocalSessionManager"
  },
  "event_data": {}
}

Event ID 60: Glass session SessionID has been reconnected to a remote protocol, this session can now only be reconnect locally or from same remote protocol.

#
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Glass session SessionID has been reconnected to a remote protocol, this session can now only be reconnect locally or from same remote protocol.

Message #

Glass session %1 has been reconnected to a remote protocol, this session can now only be reconnect locally or from same remote protocol

Fields #

NameDescription
SessionID UInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 5d896912-022d-40aa-a3a8-4fa5515c76d7

Defined in lsm.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3089, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads