Microsoft-Windows-UserPnp

EventTitleChannelSampleRule
7550New device queued up for install.SchedulerOperationsNN
7551Plug and Play install scheduler has started.SchedulerOperationsNN
7552Plug and Play install scheduler has exited.SchedulerOperationsNN
7553Plug and Play install worker thread has started.SchedulerOperationsNN
7554Plug and Play install worker thread has exited.SchedulerOperationsNN
7555Parent of current device is already ahead in the install queue.SchedulerOperationsNN
7556Current device is a volume snapshot device.SchedulerOperationsNN
7600Client {ClientName} successfully registered for device notifications.DeviceNotificationsNN
7601Error sending device event notification window message to client {WindowName} …DeviceNotificationsNN
7602Error sending service control for device event notification to client …DeviceNotificationsNN
7603Error broadcasting system message for device event notification …DeviceNotificationsNN
7604Sending notification for event {EventType} for device: {DeviceID}.DeviceNotificationsNN
7650Received device event from Kernel PnP (GUID={EventGuid}; …PerformanceNN
7651User PnP completed handling of the device event (GUID={EventGuid}; …PerformanceNN
7700Start processing 'DIF_CODE'.PerformanceNN
7701Finished processing 'DIF_CODE' (Err=ErrorCode).PerformanceNN
7702START: Core device install operations.PerformanceNN
7703END: Core device install operations.PerformanceNN
7704ENTER: Synchronization wait for core device install.PerformanceNN
7705EXIT: Synchronization wait for core device install.PerformanceNN
7708ENTER: Stage driver packagePerformanceNN
7709EXIT: Stage driver packagePerformanceNN
7714ENTER: Sending event notification to service ({ClientName}).PerformanceNN
7715EXIT: Sending event notification to service ({ClientName}).PerformanceNN
7716ENTER: Sending event notification to window ({ClientName}).PerformanceNN
7717EXIT: Sending event notification to window ({ClientName}).PerformanceNN
7718ENTER: Device installation restrictions policy check.PerformanceNN
7719EXIT: Device installation restrictions policy check.PerformanceNN
7720ENTER: Build driver info list.PerformanceNN
7721EXIT: Build driver info list.PerformanceNN
7722ENTER: Build driver info list - search published INFs.PerformanceNN
7723EXIT: Build driver info list - search published INFs.PerformanceNN
7724ENTER: Build driver info list - search Device Path.PerformanceNN
7725EXIT: Build driver info list - search Device Path.PerformanceNN
7728ENTER: Build driver info list - search caller specified folder.PerformanceNN
7729EXIT: Build driver info list - search caller specified folder.PerformanceNN
7730ENTER: PnpInstallDevice - install device instance.PerformanceNN
7731EXIT: PnpInstallDevice - install device instance.PerformanceNN
7800START: Searching WMIS for metadata packagePerformanceNN
7801STOP: Searching WMIS for metadata packagePerformanceNN
7802START: Downloading metadata package from WMISPerformanceNN
7803STOP: Downloading metadata package from WMISPerformanceNN
7804START: Searching local index for metadata packagePerformanceYN
7805STOP: Searching local index for metadata packagePerformanceYN
7806START: Unpacking metadata package into cachePerformanceNN
7807STOP: Unpacking metadata package into cachePerformanceNN
7808START: Parsing packageinfo.PerformanceNN
7809STOP: Parsing packageinfo.PerformanceNN
7810START: Scanning local store for new metadata packagesPerformanceYN
7811STOP: Scanning local store for new metadata packagesPerformanceYN
7812START: Initializing DMRCPerformanceYN
7813STOP: Initializing DMRCPerformanceYN
7814START: Uninitialize DMRCPerformanceYN
7815STOP: Uninitializing DMRCPerformanceYN
7900Message (Package: Package Error Code = ErrorCode, Win32 Error Code = …DebugNN
7901A new device metadata package was downloaded from WMIS.DebugNN
7902Message (Package: Package Error Code = ErrorCode, Win32 Error Code = …DebugNN
7903Successfully parsed device metadata file.DebugNN
7950A new device metadata package was discovered.DebugNN
7951DMRC was queried for type 'QueryType' with lookup key 'LookupKey'.DebugYN
7952Message (Error Code = NetworkErrorCode, Last Http Status Code = HttpStatusCode).DebugNN
8000A reboot is required to complete device installation of device …DeviceInstallYN
8001The DeviceInstall service has started.DeviceInstallYN
8002The DeviceInstall service is stopping (idle).DeviceInstallYN
8003The DeviceInstall service is stopping (stop control).DeviceInstallNN
8004The DeviceInstall service is stopping (shutdown).DeviceInstallYN
8005The DeviceInstall service has stopped.DeviceInstallYN
8006There are pending driver updates to install.DeviceInstallNN
8007A timeout was detected during the installation of device 'DeviceId'.DeviceInstallNN
8008The DeviceInstall service is starting.DeviceInstallYN
8009The DeviceInstall service failed to start with error ErrorCode.DeviceInstallNN
8010Finish install operation state changed to hc_stateid.ActionCenterNN
8020Device installation is currently disabled.DeviceInstallNN
8021Device installation has been disabled.DeviceInstallNN
8022Device installation has been enabled.DeviceInstallNN
8030The DeviceInstall service will not idle stop.DeviceInstallYN
8040task_08040OperationalNN
20001Driver Management concluded the process to install driver http://schemas.SystemYN
20002Driver Management concluded the process to remove driver DriverName from Device …SystemNN
20003Driver Management has concluded the process to add Service …SystemYN
20004Driver Management has concluded the process to remove Service ServiceName for …SystemNN
20005Driver Management has restricted the installation of Device Instance ID DeviceId …SystemNN
20006Driver Management has deferred the process to install Device Instance ID …SystemNN
20007Driver Management has removed Device Instance ID DeviceId because of a Device …SystemNN
20008Driver Management has not removed Device Instance ID DeviceId with matching …SystemNN
20009Driver Management will reboot the system in RebootTime seconds to enforce a …SystemNN
20010Event ID 20010SystemYN
20011Device action request for device '{VetoDevice}' was vetoed by '{VetoName}' with …SystemNN

Event ID 7550: New device queued up for install.

#
Channel
SchedulerOperations
Task
PnP_PlugPlay_DeviceInstall

Fields #

NameDescription
DeviceId UnicodeString

Event ID 7551: Plug and Play install scheduler has started.

#
Channel
SchedulerOperations
Task
PnP_PlugPlay_ProcessDeviceInstallBatch
Opcode
Start

Fields #

NameDescription
ThreadId UInt32

Event ID 7552: Plug and Play install scheduler has exited.

#
Channel
SchedulerOperations
Task
PnP_PlugPlay_ProcessDeviceInstallBatch
Opcode
Stop

Fields #

NameDescription
ThreadId UInt32

Event ID 7553: Plug and Play install worker thread has started.

#
Channel
SchedulerOperations
Task
PnP_PlugPlay_DeviceInstall

Fields #

NameDescription
ThreadId UInt32
DeviceId UnicodeString

Event ID 7554: Plug and Play install worker thread has exited.

#
Channel
SchedulerOperations
Task
PnP_PlugPlay_DeviceInstall

Fields #

NameDescription
ThreadId UInt32

Event ID 7555: Parent of current device is already ahead in the install queue.

#
Channel
SchedulerOperations
Task
PnP_PlugPlay_DeviceInstall

Fields #

NameDescription
ChildDevice UnicodeString
ParentDevice UnicodeString

Event ID 7556: Current device is a volume snapshot device.

#
Channel
SchedulerOperations
Task
PnP_PlugPlay_DeviceInstall

Fields #

NameDescription
DeviceId UnicodeString

Event ID 7600: Client {ClientName} successfully registered for device notifications.

#
Channel
DeviceNotifications

Fields #

NameDescription
ClientName

Event ID 7601: Error sending device event notification window message to client {WindowName} (hWnd={hWnd}; Session={SessionId}; Err={ErrorCode}).

#
Channel
DeviceNotifications

Fields #

NameDescription
WindowName
hWnd
SessionId
ErrorCode

Event ID 7602: Error sending service control for device event notification to client {ClientName} (Session={SessionId}; Err={ErrorCode}).

#
Channel
DeviceNotifications

Fields #

NameDescription
ClientName
SessionId
ErrorCode

Event ID 7603: Error broadcasting system message for device event notification (Err={ErrorCode}).

#
Channel
DeviceNotifications

Fields #

NameDescription
ErrorCode

Event ID 7604: Sending notification for event {EventType} for device: {DeviceID}.

#
Channel
DeviceNotifications

Fields #

NameDescription
EventType
DeviceID

Event ID 7650: Received device event from Kernel PnP (GUID={EventGuid}; EventCategory={EventCategory}; Async={IsEventAsync}).

#
Channel
Performance

Fields #

NameDescription
EventGuid
EventCategory
IsEventAsync

Event ID 7651: User PnP completed handling of the device event (GUID={EventGuid}; EventCategory={EventCategory}; Async={IsEventAsync}).

#
Channel
Performance

Fields #

NameDescription
EventGuid
EventCategory
IsEventAsync

Event ID 7700: Start processing 'DIF_CODE'.

#
Channel
Performance
Task
PnP_SetupAPI_CallClassInstaller
Opcode
Start

Message #

Start processing '%1'.

Fields #

NameDescription
DIF_CODE UnicodeString
ErrorCode HexInt32

Event ID 7701: Finished processing 'DIF_CODE' (Err=ErrorCode).

#
Channel
Performance
Task
PnP_SetupAPI_CallClassInstaller
Opcode
Stop

Message #

Finished processing '%1' (Err=%2).

Fields #

NameDescription
DIF_CODE UnicodeString
ErrorCode HexInt32

Event ID 7702: START: Core device install operations.

#
Channel
Performance
Task
PnP_Drvinst_ProcessCoreDeviceInstall
Opcode
Start

Event ID 7703: END: Core device install operations.

#
Channel
Performance
Task
PnP_Drvinst_ProcessCoreDeviceInstall
Opcode
Stop

Event ID 7704: ENTER: Synchronization wait for core device install.

#
Channel
Performance
Task
PnP_Drvinst_WaitCoreInstallMutex
Opcode
Start

Event ID 7705: EXIT: Synchronization wait for core device install.

#
Channel
Performance
Task
PnP_Drvinst_WaitCoreInstallMutex
Opcode
Stop

Event ID 7708: ENTER: Stage driver package

#
Channel
Performance
Task
PnP_SetupAPI_StageDriverPackage
Opcode
Start

Event ID 7709: EXIT: Stage driver package

#
Channel
Performance
Task
PnP_SetupAPI_StageDriverPackage
Opcode
Stop

Event ID 7714: ENTER: Sending event notification to service ({ClientName}).

#
Channel
Performance

Fields #

NameDescription
ClientName

Event ID 7715: EXIT: Sending event notification to service ({ClientName}).

#
Channel
Performance

Fields #

NameDescription
ClientName

Event ID 7716: ENTER: Sending event notification to window ({ClientName}).

#
Channel
Performance

Fields #

NameDescription
ClientName

Event ID 7717: EXIT: Sending event notification to window ({ClientName}).

#
Channel
Performance

Fields #

NameDescription
ClientName

Event ID 7718: ENTER: Device installation restrictions policy check.

#
Channel
Performance
Task
PnP_Drvinst_DevicePolicyCheck
Opcode
Start

Event ID 7719: EXIT: Device installation restrictions policy check.

#
Channel
Performance
Task
PnP_Drvinst_DevicePolicyCheck
Opcode
Stop

Event ID 7720: ENTER: Build driver info list.

#
Channel
Performance
Task
PnP_SetupAPI_BuildDriverInfoList
Opcode
Start

Event ID 7721: EXIT: Build driver info list.

#
Channel
Performance
Task
PnP_SetupAPI_BuildDriverInfoList
Opcode
Stop

Event ID 7722: ENTER: Build driver info list - search published INFs.

#
Channel
Performance
Task
PnP_SetupAPI_PublishedInfDriverSearch
Opcode
Start

Event ID 7723: EXIT: Build driver info list - search published INFs.

#
Channel
Performance
Task
PnP_SetupAPI_PublishedInfDriverSearch
Opcode
Stop

Event ID 7724: ENTER: Build driver info list - search Device Path.

#
Channel
Performance
Task
PnP_SetupAPI_DevicePathDriverSearch
Opcode
Start

Event ID 7725: EXIT: Build driver info list - search Device Path.

#
Channel
Performance
Task
PnP_SetupAPI_DevicePathDriverSearch
Opcode
Stop

Event ID 7728: ENTER: Build driver info list - search caller specified folder.

#
Channel
Performance
Task
PnP_SetupAPI_FolderDriverSearch
Opcode
Start

Event ID 7729: EXIT: Build driver info list - search caller specified folder.

#
Channel
Performance
Task
PnP_SetupAPI_FolderDriverSearch
Opcode
Stop

Event ID 7730: ENTER: PnpInstallDevice - install device instance.

#
Channel
Performance
Task
PnP_PlugPlay_PnpInstallDevice
Opcode
Start

Event ID 7731: EXIT: PnpInstallDevice - install device instance.

#
Channel
Performance
Task
PnP_PlugPlay_PnpInstallDevice
Opcode
Stop

Event ID 7800: START: Searching WMIS for metadata package

#
Channel
Performance
Task
PnP_DMRC_SearchWMIS
Opcode
Start

Event ID 7801: STOP: Searching WMIS for metadata package

#
Channel
Performance
Task
PnP_DMRC_SearchWMIS
Opcode
Stop

Event ID 7802: START: Downloading metadata package from WMIS

#
Channel
Performance
Task
PnP_DMRC_DownloadPackage
Opcode
Start

Event ID 7803: STOP: Downloading metadata package from WMIS

#
Channel
Performance
Task
PnP_DMRC_DownloadPackage
Opcode
Stop

Event ID 7804: START: Searching local index for metadata package

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_SearchLocalIndex
Opcode
Start

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7804,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11720,
      "thread_id": 11376
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:59:31.472Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7805: STOP: Searching local index for metadata package

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_SearchLocalIndex
Opcode
Stop

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7805,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11720,
      "thread_id": 11376
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:59:31.472Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7806: START: Unpacking metadata package into cache

#
Channel
Performance
Task
PnP_DMRC_UnpackPackage
Opcode
Start

Event ID 7807: STOP: Unpacking metadata package into cache

#
Channel
Performance
Task
PnP_DMRC_UnpackPackage
Opcode
Stop

Event ID 7808: START: Parsing packageinfo.

#
Channel
Performance
Task
PnP_DMRC_ParsePackageInfo
Opcode
Start

Description

START: Parsing packageinfo.xml for metadata properties.

Message #

START: Parsing packageinfo.xml for metadata properties

Event ID 7809: STOP: Parsing packageinfo.

#
Channel
Performance
Task
PnP_DMRC_ParsePackageInfo
Opcode
Stop

Description

STOP: Parsing packageinfo.xml for metadata properties.

Message #

STOP: Parsing packageinfo.xml for metadata properties

Event ID 7810: START: Scanning local store for new metadata packages

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_ScanLocalStore
Opcode
Start

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7810,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11720,
      "thread_id": 11376
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:59:31.470Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7811: STOP: Scanning local store for new metadata packages

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_ScanLocalStore
Opcode
Stop

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7811,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11720,
      "thread_id": 11376
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:59:31.471Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7812: START: Initializing DMRC

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_Initialize
Opcode
Start

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7812,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11720,
      "thread_id": 11376
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:59:31.468Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7813: STOP: Initializing DMRC

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_Initialize
Opcode
Stop

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7813,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11720,
      "thread_id": 11376
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:59:31.471Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7814: START: Uninitialize DMRC

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_Uninitialize
Opcode
Start

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7814,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 8428,
      "thread_id": 2112
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:58:57.997Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7815: STOP: Uninitializing DMRC

#
Channel
Performance
Level
Informational
Task
PnP_DMRC_Uninitialize
Opcode
Stop

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7815,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 8428,
      "thread_id": 2112
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:58:58.020Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 7900: Message (Package: Package Error Code = ErrorCode, Win32 Error Code = Win32ErrorCode).

#
Channel
Debug
Task
PnP_DMRC_ParseMetadata

Message #

%1 (Package: %2 Error Code = %3, Win32 Error Code = %4)

Fields #

NameDescription
Message UnicodeString
Package UnicodeString
ErrorCode HexInt32
Win32ErrorCode HexInt32

Event ID 7901: A new device metadata package was downloaded from WMIS.

#
Channel
Debug
Task
PnP_DMRC_Query

Description

A new device metadata package was downloaded from WMIS. (Path: PackagePath).

Message #

A new device metadata package was downloaded from WMIS. (Path: %1)

Fields #

NameDescription
PackagePath UnicodeString

Event ID 7902: Message (Package: Package Error Code = ErrorCode, Win32 Error Code = Win32ErrorCode).

#
Channel
Debug
Task
PnP_DMRC_ParseMetadata

Message #

%1 (Package: %2 Error Code = %3, Win32 Error Code = %4)

Fields #

NameDescription
Message UnicodeString
Package UnicodeString
ErrorCode HexInt32
Win32ErrorCode HexInt32

Event ID 7903: Successfully parsed device metadata file.

#
Channel
Debug
Task
PnP_DMRC_ParseMetadata

Description

Successfully parsed device metadata file. (File: File, Language: Language).

Message #

Successfully parsed device metadata file. (File: %1, Language: %2)

Fields #

NameDescription
File UnicodeString
Language UnicodeString

Event ID 7950: A new device metadata package was discovered.

#
Channel
Debug
Task
PnP_DMRC_ParseMetadata

Description

A new device metadata package was discovered. (Package Name: PackageName, Path: PackagePath).

Message #

A new device metadata package was discovered. (Package Name: %1, Path: %2)

Fields #

NameDescription
PackageName UnicodeString
PackagePath UnicodeString

Event ID 7951: DMRC was queried for type 'QueryType' with lookup key 'LookupKey'.

#
Channel
Debug
Level
Informational
Task
PnP_DMRC_Query

Message #

DMRC was queried for type '%1' with lookup key '%2'

Fields #

NameDescription
QueryType UnicodeString
LookupKey UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-UserPnp/DeviceMetadata/Debug",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 7951,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11720,
      "thread_id": 11376
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-UserPnp",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 01:59:31.472Z",
    "version": 0
  },
  "event_data": {
    "LookupKey": "ComputerMetadata\\{CA0957D0-549A-5699-84D5-1C8A462925A4}",
    "QueryType": "Hardware Id (display object)"
  },
  "message": ""
}

Event ID 7952: Message (Error Code = NetworkErrorCode, Last Http Status Code = HttpStatusCode).

#
Channel
Debug
Task
PnP_DMRC_Query

Message #

%1 (Error Code = %2, Last Http Status Code = %3)

Fields #

NameDescription
Message UnicodeString
NetworkErrorCode HexInt32
HttpStatusCode UInt32

Event ID 8000: A reboot is required to complete device installation of device 'ERR_DEVICE_ID.DeviceId'.

#
Channel
DeviceInstall
Level
Warning

Message #

A reboot is required to complete device installation of device '%1'

Fields #

NameDescription
DeviceId

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
    "event_source_name": "",
    "event_id": 8000,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 576460752303423490,
    "time_created": "2023-10-25T22:50:39.873740+00:00",
    "event_record_id": 21,
    "correlation": {},
    "execution": {
      "process_id": 3600,
      "thread_id": 1060
    },
    "channel": "Microsoft-Windows-UserPnp/DeviceInstall",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "ERR_DEVICE_ID": {
      "DeviceId": "ACPI\\VMW0003\\4&1BD7F811&0"
    }
  },
  "message": ""
}

References #

Event ID 8001: The DeviceInstall service has started.

#
Channel
DeviceInstall
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "{96F4A050-7E31-453C-88BE-9634F4E02139}",
    "event_source_name": "",
    "event_id": 8001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 576460752303423490,
    "time_created": "2026-05-28T04:47:58.4674435+00:00",
    "event_record_id": 13,
    "correlation": {},
    "execution": {
      "process_id": 4536,
      "thread_id": 5956
    },
    "channel": "Microsoft-Windows-UserPnp/DeviceInstall",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The DeviceInstall service has started."
}

Event ID 8002: The DeviceInstall service is stopping (idle).

#
Channel
DeviceInstall
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "{96F4A050-7E31-453C-88BE-9634F4E02139}",
    "event_source_name": "",
    "event_id": 8002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 576460752303423490,
    "time_created": "2026-05-28T04:50:31.7833993+00:00",
    "event_record_id": 14,
    "correlation": {},
    "execution": {
      "process_id": 4536,
      "thread_id": 2572
    },
    "channel": "Microsoft-Windows-UserPnp/DeviceInstall",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The DeviceInstall service is stopping (idle)."
}

Event ID 8003: The DeviceInstall service is stopping (stop control).

#
Channel
DeviceInstall

Event ID 8004: The DeviceInstall service is stopping (shutdown).

#
Channel
DeviceInstall
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
    "event_source_name": "",
    "event_id": 8004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 576460752303423490,
    "time_created": "2023-11-06T06:23:40.089953+00:00",
    "event_record_id": 27,
    "correlation": {},
    "execution": {
      "process_id": 1068,
      "thread_id": 1072
    },
    "channel": "Microsoft-Windows-UserPnp/DeviceInstall",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 8005: The DeviceInstall service has stopped.

#
Channel
DeviceInstall
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "{96F4A050-7E31-453C-88BE-9634F4E02139}",
    "event_source_name": "",
    "event_id": 8005,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 576460752303423490,
    "time_created": "2026-05-28T04:50:31.7839977+00:00",
    "event_record_id": 15,
    "correlation": {},
    "execution": {
      "process_id": 4536,
      "thread_id": 2572
    },
    "channel": "Microsoft-Windows-UserPnp/DeviceInstall",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The DeviceInstall service has stopped."
}

Event ID 8006: There are pending driver updates to install.

#
Channel
DeviceInstall

Event ID 8007: A timeout was detected during the installation of device 'DeviceId'.

#
Channel
DeviceInstall

Message #

A timeout was detected during the installation of device '%1'

Fields #

NameDescription
DeviceId UnicodeString

Event ID 8008: The DeviceInstall service is starting.

#
Channel
DeviceInstall
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
    "event_source_name": "",
    "event_id": 8008,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 576460752303423490,
    "time_created": "2023-11-06T06:25:29.340577+00:00",
    "event_record_id": 29,
    "correlation": {},
    "execution": {
      "process_id": 1080,
      "thread_id": 1096
    },
    "channel": "Microsoft-Windows-UserPnp/DeviceInstall",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 8009: The DeviceInstall service failed to start with error ErrorCode.

#
Channel
DeviceInstall

Message #

The DeviceInstall service failed to start with error %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 8010: Finish install operation state changed to hc_stateid.

#
Channel
ActionCenter
Task
FinishInstallOperationsstatehaschanged.

Message #

Finish install operation state changed to %1.

Fields #

NameDescription
hc_stateid UInt32

Event ID 8020: Device installation is currently disabled.

#
Channel
DeviceInstall

Event ID 8021: Device installation has been disabled.

#
Channel
DeviceInstall

Event ID 8022: Device installation has been enabled.

#
Channel
DeviceInstall

Event ID 8030: The DeviceInstall service will not idle stop.

#
Channel
DeviceInstall
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
    "event_source_name": "",
    "event_id": 8030,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 576460752303423490,
    "time_created": "2023-11-06T06:25:29.352092+00:00",
    "event_record_id": 31,
    "correlation": {},
    "execution": {
      "process_id": 1080,
      "thread_id": 1096
    },
    "channel": "Microsoft-Windows-UserPnp/DeviceInstall",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 8040: task_08040

#
Channel
Operational

Fields #

NameDescription
DeviceInstanceId UnicodeString
HardwareIds UnicodeString
CompatibleIds UnicodeString
MatchingDeviceId UnicodeString
OriginalInfName UnicodeString
DriverDate FILETIME
DriverVersion UnicodeString
SubmissionId UnicodeString
FlightIds UnicodeString

Event ID 20001: Driver Management concluded the process to install driver http://schemas.

#
Channel
System
Level
Informational
Task
PnP_PlugPlay_DeviceInstall

Description

Driver Management concluded the process to install driver for Device Instance ID with the following status: .

Message #

Driver Management concluded the process to install driver %1 for Device Instance ID %4 with the following status: %9.

Fields #

NameDescription
DriverName
DriverVersion
DriverProvider
DeviceInstanceID
SetupClass
RebootOption
UpgradeDevice
IsDriverOEM
InstallStatus
DriverDescription

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
    "event_source_name": "",
    "event_id": 20001,
    "version": 0,
    "level": 4,
    "task": 7005,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2013-10-23T16:17:53.968750+00:00",
    "event_record_id": 250,
    "correlation": {},
    "execution": {
      "process_id": 1536,
      "thread_id": 1900
    },
    "channel": "System",
    "computer": "37L4247D28-05",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "InstallDeviceID": {
      "xmlns:auto-ns2": "http://schemas.microsoft.com/win/2004/08/events",
      "DriverName": "FileRepository\\rdpbus.inf_x86_neutral_27637529205407be\\rdpbus.inf",
      "DriverVersion": "6.1.7600.16385",
      "DriverProvider": "Microsoft",
      "DeviceInstanceID": "ROOT\\RDPBUS\\0000",
      "SetupClass": "4D36E97D-E325-11CE-BFC1-08002BE10318",
      "RebootOption": false,
      "UpgradeDevice": false,
      "IsDriverOEM": false,
      "InstallStatus": 0,
      "DriverDescription": "Remote Desktop Device Redirector Bus"
    }
  },
  "message": "Driver Management concluded the process to install driver http://schemas.microsoft.com/win/2004/08/events for Device Instance ID Microsoft with the following status: false."
}

References #

Event ID 20002: Driver Management concluded the process to remove driver DriverName from Device Instance ID DeviceInstanceID with the following status: InstallStatus.

#
Channel
System
Task
PnP_PlugPlay_DeviceInstall

Message #

Driver Management concluded the process to remove driver %1 from Device Instance ID %4 with the following status: %9.

Fields #

NameDescription
DriverName UnicodeString
DriverVersion UnicodeString
DriverProvider UnicodeString
DeviceInstanceID UnicodeString
SetupClass GUID
RebootOption Boolean
UpgradeDevice Boolean
IsDriverOEM Boolean
InstallStatus HexInt32
DriverDescription UnicodeString

Event ID 20003: Driver Management has concluded the process to add Service AddServiceID.ServiceName for Device Instance ID AddServiceID.DeviceInstanceID with the following status: AddServiceID.AddServiceStatus.

#
Channel
System
Level
Informational
Task
PnP_PlugPlay_DeviceInstall

Message #

Driver Management has concluded the process to add Service %1 for Device Instance ID %3 with the following status: %6.

Fields #

NameDescription
ServiceName
DriverFileName
DeviceInstanceID
PrimaryService
UpdateService
AddServiceStatus

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
    "event_source_name": "",
    "event_id": 20003,
    "version": 0,
    "level": 4,
    "task": 7005,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T22:30:40.551666+00:00",
    "event_record_id": 1844,
    "correlation": {},
    "execution": {
      "process_id": 7864,
      "thread_id": 8460
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "AddServiceID": {
      "ServiceName": "VM3DService",
      "DriverFileName": "%SystemRoot%\\system32\\vm3dservice.exe",
      "DeviceInstanceID": "PCI\\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\\3&61AAA01&0&78",
      "PrimaryService": false,
      "UpdateService": false,
      "AddServiceStatus": 0
    }
  },
  "message": ""
}

References #

Event ID 20004: Driver Management has concluded the process to remove Service ServiceName for Device Instance ID DeviceInstanceID with the following status: AddServiceStatus.

#
Channel
System
Task
PnP_PlugPlay_DeviceInstall

Message #

Driver Management has concluded the process to remove Service %1 for Device Instance ID %3 with the following status: %6.

Fields #

NameDescription
ServiceName UnicodeString
DriverFileName UnicodeString
DeviceInstanceID UnicodeString
PrimaryService Boolean
UpdateService Boolean
AddServiceStatus UInt32

Event ID 20005: Driver Management has restricted the installation of Device Instance ID DeviceId because of a Device Installation Restriction policy setting.

#
Channel
System
Task
PnP_PlugPlay_DeviceInstall

Message #

Driver Management has restricted the installation of Device Instance ID %1 because of a Device Installation Restriction policy setting.

Fields #

NameDescription
DeviceId UnicodeString

Event ID 20006: Driver Management has deferred the process to install Device Instance ID DeviceId until a driver has been selected because of a Device Installation Restr...

#
Channel
System
Task
PnP_PlugPlay_DeviceInstall

Description

Driver Management has deferred the process to install Device Instance ID DeviceId until a driver has been selected because of a Device Installation Restriction policy setting.

Message #

Driver Management has deferred the process to install Device Instance ID %1 until a driver has been selected because of a Device Installation Restriction policy setting.

Fields #

NameDescription
DeviceId UnicodeString

Event ID 20007: Driver Management has removed Device Instance ID DeviceId because of a Device Installation Restriction policy setting.

#
Channel
System
Task
PnP_PlugPlay_DeviceInstall

Message #

Driver Management has removed Device Instance ID %1 because of a Device Installation Restriction policy setting.

Fields #

NameDescription
DeviceId UnicodeString

Event ID 20008: Driver Management has not removed Device Instance ID DeviceId with matching policy restriction because it is a required system device.

#
Channel
System
Task
PnP_PlugPlay_DeviceInstall

Message #

Driver Management has not removed Device Instance ID %1 with matching policy restriction because it is a required system device.

Fields #

NameDescription
DeviceId UnicodeString

Event ID 20009: Driver Management will reboot the system in RebootTime seconds to enforce a Device Installation Restriction policy setting.

#
Channel
System
Task
PnP_PlugPlay_DeviceInstall

Message #

Driver Management will reboot the system in %1 seconds to enforce a Device Installation Restriction policy setting.

Fields #

NameDescription
RebootTime UInt32

Event ID 20010

#
Channel
System
Level
Informational

Fields #

NameDescription
INFO_PNP_STATE.xmlns:auto-ns2
INFO_PNP_STATE.InstallSubsystemState
INFO_PNP_STATE.CachingSubsystemState

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-UserPnp",
    "guid": "96F4A050-7E31-453C-88BE-9634F4E02139",
    "event_source_name": "",
    "event_id": 20010,
    "version": 0,
    "level": 4,
    "task": 7010,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2013-10-23T16:18:04.750000+00:00",
    "event_record_id": 255,
    "correlation": {},
    "execution": {
      "process_id": 616,
      "thread_id": 1644
    },
    "channel": "System",
    "computer": "37L4247D28-05",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "INFO_PNP_STATE": {
      "xmlns:auto-ns2": "http://schemas.microsoft.com/win/2004/08/events",
      "InstallSubsystemState": true,
      "CachingSubsystemState": true
    }
  },
  "message": ""
}

References #

Event ID 20011: Device action request for device '{VetoDevice}' was vetoed by '{VetoName}' with veto type {VetoType}.

#
Channel
System

Fields #

NameDescription
VetoDevice
VetoName
VetoType

Provenance

ETW provider GUID 96f4a050-7e31-453c-88be-9634f4e02139

Defined in umpnpmgr.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB