Microsoft-Windows-UserDataAccess-Poom
29 events across 1 channel
Event ID 1: Error: P1_HResult Location: P2_String Line Number: P3_UInt32.
#Event ID 2: Error Propagated: P1_HResult Location: P2_String Line Number: P3_UInt32.
#Event ID 2000: ScheduleExternalNotify: CeRunAppAtTime executed, Process: Prop_Process_UnicodeString GetLastError: Prop_ErrorCode.
#Event ID 2002: SetProperty failed for property = Prop_Handle, Flag = Prop_HRESULT, Error = Prop_UINT.
#Event ID 2003: Validate failed for property = Prop_Handle, Error = Prop_HRESULT.
#Event ID 2008: POOM AggregateCache is being rebuilt.
#Description
POOM AggregateCache is being rebuilt.
Message #
Event ID 2009: POOM AggregateCache is being backed up to file, size is Prop_UInt32 bytes.
#Event ID 2010: POOM Store being deleted id = Prop_UInt32.
#Event ID 2011: POOM Folder being deleted type = Prop_Handle, store = Prop_HRESULT, id = Prop_UINT.
#Event ID 2012: CALSTORE setting global object id with size = Prop_Handle, store = Prop_HRESULT, id = Prop_UINT.
#Event ID 2013: CALSTORE creating appointment with no GlobjId enumtype = Prop_UInt32.
#Event ID 2014: CALSTORE getting global object id with size = Prop_HexInt1, found = Prop_Bool, store = Prop_HexInt2, id = Prop_HexInt3.
#Event ID 2016: Aggregate Get Picture Path, ContactId: P1_UInt32 Path: P2_String PropId: P3_UInt32.
#Event ID 2017: Contact Set Picture, ContactId: P1_UInt32 Path: P2_String PropId: P3_UInt32 Type: P4_UInt32.
#Event ID 2018: Contact Set Picture Stream, ContactId: Prop_UInt32 PropId Prop_Hex_UInt32.
#Event ID 2019: Fill String prop out of memory, PropId: P1_HexInt New Val: P2_UnicodeString.
#Event ID 2020: POOM AggregateCache Get Generation Value Prop_UInt32.
#Event ID 2021: POOM AggregateCache Set Generation Value Prop_UInt32.
#Event ID 2022: Invalid recurrence type (Prop_UInt32) for Appt (Prop_Hex_UInt32).
#Event ID 5000: Critical Section Prop_CriticalSection_Name was held for Prop_TimeHeld milliseconds.
#Event ID 5001: Prop_UInt32: Function Ptr: Prop_Hex_UInt32.
#Event ID 6000: Snapshot generation started for: {P1_UInt32.
#Event ID 6001: Snapshot generation completed for: {P1_UInt32.
#Event ID 6002: Snapshot generation started for: {P1_UInt32.
#Event ID 6003: Snapshot generation completed for: {P1_UInt32.
#Event ID 6004: SODA_ActivitySnapshot_MergeFeedStart
#Event ID 6005: SODA_ActivitySnapshot_MergeFeedStop
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 0bd19909-eb6f-4b16-8074-6dce803f091d
Defined in pimstore.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, captured 2026-06-02