Microsoft-Windows-UserDataAccess-CEMAPI
141 events across 1 channel
Event ID 1: Error: P1_HResult Location: P2_String Line Number: P3_UInt32.
#Event ID 2: Error Propagated: P1_HResult Location: P2_String Line Number: P3_UInt32.
#Event ID 4011: FOLDER_EMPTYFOLDERStart
#Event ID 4012: FOLDER_EMPTYFOLDERStop
#Event ID 4013: FOLDER_CREATEMESSAGEStart
#Event ID 4014: FOLDER_CREATEMESSAGEStop
#Event ID 4015: FOLDER_DELETEMESSAGESStart
#Event ID 4016: FOLDER_DELETEMESSAGESStop
#Event ID 4017: FOLDER_COPYMESSAGESStart
#Event ID 4018: FOLDER_COPYMESSAGESStop
#Event ID 4019: FOLDER_GETHIERARCHYTABLEStart
#Event ID 4020: FOLDER_GETHIERARCHYTABLEStop
#Event ID 4021: FOLDER_GETCONTENTSTABLEStart
#Event ID 4022: FOLDER_GETCONTENTSTABLEStop
#Event ID 4023: FOLDER_DELETEFOLDERStart
#Event ID 4024: FOLDER_DELETEFOLDERStop
#Event ID 4025: FOLDER_COPYFOLDERStart
#Event ID 4026: FOLDER_COPYFOLDERStop
#Event ID 4027: FOLDER_CREATEFOLDERStart
#Event ID 4028: FOLDER_CREATEFOLDERStop
#Event ID 4100: QUERYROWS_ATTACHMENTSStart
#Event ID 4101: QUERYROWS_ATTACHMENTSStop
#Event ID 4102: QUERYROWS_RECIPIENTSStart
#Event ID 4103: QUERYROWS_RECIPIENTSStop
#Event ID 4104: QUERYROWS_FOLDERCONTENTSStart
#Event ID 4105: QUERYROWS_FOLDERCONTENTSStop
#Event ID 4106: QUERYROWS_FOLDERHIERARCHYStart
#Event ID 4107: QUERYROWS_FOLDERHIERARCHYStop
#Event ID 4108: QUERYROWS_SEARCHFOLDERStart
#Event ID 4109: QUERYROWS_SEARCHFOLDERStop
#Event ID 4110: QUERYROWS_STORESStart
#Event ID 4111: QUERYROWS_STORESStop
#Event ID 4112: QUERYROWS_CONVERSATIONSStart
#Event ID 4113: QUERYROWS_CONVERSATIONSStop
#Event ID 4200: STORE_GETIDSFROMNAMESStart
#Event ID 4201: STORE_GETIDSFROMNAMESStop
#Event ID 4202: STORE_OPENFOLDERStart
#Event ID 4203: STORE_OPENFOLDERStop
#Event ID 4204: STORE_OPENMESSAGEStart
#Event ID 4205: STORE_OPENMESSAGEStop
#Event ID 4206: STORE_ISANCESTORStart
#Event ID 4207: STORE_ISANCESTORStop
#Event ID 4208: STORE_CREATESPECIALFOLDERSStart
#Event ID 4209: STORE_CREATESPECIALFOLDERSStop
#Event ID 4210: STORE_LOADRULESLISTStart
#Event ID 4211: STORE_LOADRULESLISTStop
#Event ID 4212: STORE_RUNRULESStart
#Event ID 4213: STORE_RUNRULESStop
#Event ID 4300: MAPILOGONEXStart
#Event ID 4301: MAPILOGONEXStop
#Event ID 4302: CTX_GETSTOREMANAGERStart
#Event ID 4303: CTX_GETSTOREMANAGERStop
#Event ID 4304: CTX_CREATESESSIONStart
#Event ID 4305: CTX_CREATESESSIONStop
#Event ID 4306: CTX_CREATEINSTANCEStart
#Event ID 4307: CTX_CREATEINSTANCEStop
#Event ID 4308: CTX_INITMESSAGESTORESStart
#Event ID 4309: CTX_INITMESSAGESTORESStop
#Event ID 4310: CTX_CREATESMSSTOREStart
#Event ID 4311: CTX_CREATESMSSTOREStop
#Event ID 4312: CTX_LOADDEFAULTMESSAGESTOREStart
#Event ID 4313: CTX_LOADDEFAULTMESSAGESTOREStop
#Event ID 4314: CTX_CREATEMESSAGESTOREStart
#Event ID 4315: CTX_CREATEMESSAGESTOREStop
#Event ID 4316: CTX_OPENENTRYStart
#Event ID 4317: CTX_OPENENTRYStop
#Event ID 4318: CTX_ADVISEStart
#Event ID 4319: CTX_ADVISEStop
#Event ID 4320: CTX_UNADVISEStart
#Event ID 4321: CTX_UNADVISEStop
#Event ID 4322: CTX_INITSTORESINKStart
#Event ID 4323: CTX_INITSTORESINKStop
#Event ID 4324: CTX_GETSTOREBYIDStart
#Event ID 4325: CTX_GETSTOREBYIDStop
#Event ID 4326: CTX_GETSTOREFROMDATABASEStart
#Event ID 4327: CTX_GETSTOREFROMDATABASEStop
#Event ID 4328: CTX_OPENMSGSTOREStart
#Event ID 4329: CTX_OPENMSGSTOREStop
#Event ID 4330: CTX_DELETEMSGSTOREStart
#Event ID 4331: CTX_DELETEMSGSTOREStop
#Event ID 4332: CTX_REFRESHRULECLIENTSStart
#Event ID 4333: CTX_REFRESHRULECLIENTSStop
#Event ID 4400: MSG_CREATEATTACHStart
#Event ID 4401: MSG_CREATEATTACHStop
#Event ID 4402: MSG_DELETEATTACHStart
#Event ID 4403: MSG_DELETEATTACHStop
#Event ID 4404: MSG_OPENATTACHStart
#Event ID 4405: MSG_OPENATTACHStop
#Event ID 4406: MSG_GETATTACHTABLEStart
#Event ID 4407: MSG_GETATTACHTABLEStop
#Event ID 4408: MSG_MODIFYRECIPIENTSStart
#Event ID 4409: MSG_MODIFYRECIPIENTSStop
#Event ID 4410: MSG_SUBMITMESSAGEStart
#Event ID 4411: MSG_SUBMITMESSAGEStop
#Event ID 4412: MSG_DELETERECIPIENTSStart
#Event ID 4413: MSG_DELETERECIPIENTSStop
#Event ID 4414: MSG_ADDRECIPIENTSStart
#Event ID 4415: MSG_ADDRECIPIENTSStop
#Event ID 4416: MSG_UPDATERECIPIENTTABLEStart
#Event ID 4417: MSG_UPDATERECIPIENTTABLEStop
#Event ID 4418: MSG_PREPROCESSWRITEStart
#Event ID 4419: MSG_PREPROCESSWRITEStop
#Event ID 4420: MSG_POSTPROCESSWRITEStart
#Event ID 4421: MSG_POSTPROCESSWRITEStop
#Event ID 4500: SETPROPSStart
#Event ID 4501: SETPROPSStop
#Event ID 4502: GETPROPSStart
#Event ID 4503: GETPROPSStop
#Event ID 4504: DELETEPROPSStart
#Event ID 4505: DELETEPROPSStop
#Event ID 4506: OPENSTREAMPROPERTYStart
#Event ID 4507: OPENSTREAMPROPERTYStop
#Event ID 4508: RUNRULEStart
#Event ID 4509: RUNRULEStop
#Event ID 4510: SESSION_GETSTORESTABLEStart
#Event ID 4511: SESSION_GETSTORESTABLEStop
#Event ID 4512: SINK_ONNOTIFYStart
#Event ID 4513: SINK_ONNOTIFYStop
#Event ID 4514: SINK_ONNOTIFYWRAPPERStart
#Event ID 4515: SINK_ONNOTIFYWRAPPERStop
#Event ID 4600: CONVERSATION_DELETEStart
#Event ID 4601: CONVERSATION_DELETEStop
#Event ID 4602: CONVERSATION_SOFTDELETEStart
#Event ID 4603: CONVERSATION_SOFTDELETEStop
#Event ID 4604: CONVERSATION_MSGPROPSETStart
#Event ID 4605: CONVERSATION_MSGPROPSETStop
#Event ID 4606: CONVERSATION_MSGPROPDELETEStart
#Event ID 4607: CONVERSATION_MSGPROPDELETEStop
#Event ID 4608: CONVERSATION_DELETEMESSAGESStart
#Event ID 4609: CONVERSATION_DELETEMESSAGESStop
#Event ID 4610: CONVERSATIONID_SETStart
#Event ID 4611: CONVERSATIONID_SETStop
#Event ID 4612: CONVERSATIONID_CREATEHASHStart
#Event ID 4613: CONVERSATIONID_CREATEHASHStop
#Event ID 4700: SHARECONTENTStart
#Event ID 4701: SHARECONTENTStop
#Event ID 4803: Unknown prop tag seen in ConvertDatabasePropertyTagsToMapiTags: Prop_Hex_UInt32.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 83a9277a-d2fc-4b34-bf81-8ceb4407824f
Defined in cemapi.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, captured 2026-06-02