Microsoft-Windows-Wcmsvc

EventTitleChannelSampleRule
1001WCMSVC: Service StartupOperationalNN
1002WCMSVC: Service ShutdownOperationalNN
1003CDE reported a state change.OperationalYN
1004A Group Policy change was processedOperationalYN
1005A Power change was processed.OperationalNN
1006A Terminal Services session change was processed.OperationalYN
1007CDE reported a state change.DiagnosticNN
1008NLA interface property change.DiagnosticNN
1009CDE reported an L2 adapter arrival.OperationalYN
1010CDE reported an L2 adapter removal.OperationalYN
1011CDE reported a successful connection.DiagnosticNN
1012CDE reported a connection failure.OperationalNN
1013CDE reported a disconnection.DiagnosticNN
1014WcmSetParameter Called.DiagnosticYN
1015Interface Token Applied.OperationalNN
1016Interface Token Failed.OperationalNN
1017Soft disconnect over thresholds for interface: InterfaceGUID.OperationalNN
1018Soft disconnect under thresholds for interface: InterfaceGUID.OperationalNN
1019CDE reported an unblocked profile.OperationalNN
1020WCM Preferred Order List.OperationalYN
1022WCM entered connected standbyOperationalNN
1023WCM exited connected standbyOperationalNN
1024Acquired NDIS NIC Active Reference for interface: InterfaceGUID.DiagnosticNN
1025Released NDIS NIC Active Reference for interface: InterfaceGUID.DiagnosticNN
1026CDE reported an NDIS adapter arrival.OperationalYN
1027CDE reported an NDIS adapter removal.OperationalYN
1028WCM entered net quiet modeOperationalNN
1029WCM exited net quiet modeOperationalNN
1030Billing Cycle Reset SuccessfulOperationalNN
1031Server Time Retrieval FailureOperationalNN
1032Acquire NDIS NIC Active Reference Failed for interface: InterfaceGUID.OperationalNN
1033Release NDIS NIC Active Reference Failed for interface: InterfaceGUID.OperationalNN
1034OnDemandInterfaceStateChanged.OperationalNN
1035OnDemand PDP Profile Created.DiagnosticNN
1036OnDemand PDP Profile Deleted.DiagnosticNN
1037OnDemand Request opened.OperationalNN
1038OnDemand Request closed.OperationalNN
1039OnDemand Request started.DiagnosticNN
1040OnDemand Request cancelled.DiagnosticNN
1050WcmSvc acquired the NIC reference for Interface: InterfaceGUID for reason: …DiagnosticNN
1051WcmSvc released the NIC reference for Interface: InterfaceGUID for reason: …DiagnosticNN
1052WcmSvc signalled disconnected standbyOperationalNN
1053WcmSvc signalled end of disconnected standbyOperationalNN
1054WcmSvc received power policy update for networking in standby - the new policy …OperationalNN
4020End of Wwan Resume ReconnectDiagnosticNN
4021End of Wlan Resume Reconnect to Same NetworkDiagnosticNN
4022End of Wlan Resume Reconnect to Same Network OneXDiagnosticNN
4023End of Wlan Resume Reconnect to Different NetworkDiagnosticNN
4024End of Wlan Resume Reconnect to Different Network OneXDiagnosticNN
4025Cancel of Wlan Resume Reconnect2DiagnosticNN
4026Measure WWAN Resume Reconnect taskDiagnosticNN
4027WcmSvc CmPdcActivationClientRegister - Status [Status].OperationalNN
4028WcmSvc CmPdcActivationClientUnregister - Status [Status].OperationalNN
4029WcmSvc CmPdcActivationClientActivityRequest - Activate [Activity], Status …OperationalNN
4030WcmSvc SetNetworkReference - Activate [Activate], Result [Result], …OperationalNN
4031WcmSvc ReleaseNetworkReferenceInProcess - ProcessId [ProcessId], …OperationalNN
4032WcmSvc AcquireNdisReference - Result [Result], TotalCmNdisRefCount …OperationalNN
4033WcmSvc ReleaseNdisReference - Result [Result], TotalCmNdisRefCount …OperationalNN
4034WcmSvc ReleaseNdisReferenceInProcess - ProcessId [ProcessId], …OperationalNN
4035WcmSvc NdisReferenceError - [FunctionName]: Result [Error].OperationalNN
4036CmService::NdisReference - [AcquireRelease] InterfaceLuid [InterfaceLuid], …OperationalNN
10001WCMSVC: Start WCM Service StartupOperationalYN
10002WCMSVC: Complete WCM Service StartupOperationalYN
10003WCMSVC: Start Service ShutdownOperationalYN
10004WCMSVC: Complete Service ShutdownOperationalYN
10005Tethering Manager Loaded SuccessfullyDiagnosticNN
10006Tethering Manager Unloaded SuccessfullyDiagnosticNN

Event ID 1001: WCMSVC: Service Startup

#
Channel
Operational
Opcode
Info

Event ID 1002: WCMSVC: Service Shutdown

#
Channel
Operational
Opcode
Info

Event ID 1003: CDE reported a state change.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

CDE reported a state change 

 State: %1 

 Name: %2

Fields #

NameDescription
Status UInt32NTSTATUS reference
Name UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
    "event_source_name": "",
    "event_id": 1003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775840,
    "time_created": "2023-11-06T06:25:42.259570+00:00",
    "event_record_id": 100,
    "correlation": {},
    "execution": {
      "process_id": 2540,
      "thread_id": 3204
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "Status": 1,
    "Name": 2
  },
  "message": ""
}

References #

Event ID 1004: A Group Policy change was processed

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 1004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T06:21:48.6534269+00:00",
    "event_record_id": 98,
    "correlation": {},
    "execution": {
      "process_id": 2204,
      "thread_id": 4052
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "A Group Policy change was processed"
}

Event ID 1005: A Power change was processed.

#
Channel
Operational
Opcode
Info

Message #

A Power change was processed. 

 Reason: %1

Fields #

NameDescription
Reason UInt32

Event ID 1006: A Terminal Services session change was processed.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

A Terminal Services session change was processed. 

 Reason: %1

Fields #

NameDescription
Reason UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 1006,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775776,
    "time_created": "2026-05-29T16:33:57.0710322+00:00",
    "event_record_id": 110,
    "correlation": {},
    "execution": {
      "process_id": 2992,
      "thread_id": 3064
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "Reason": "5"
  },
  "message": "A Terminal Services session change was processed. \r\n\r\n Reason: A user has logged on to the session"
}

Event ID 1007: CDE reported a state change.

#
Channel
Diagnostic
Opcode
Info

Message #

CDE reported a state change 

 State: %1 

 Name: Nlasvc.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1008: NLA interface property change.

#
Channel
Diagnostic
Opcode
Info

Message #

NLA interface property change 

Interface: %1
Internet v4: %2
Internet v6: %3
Probe Complete v4: %4
Probe Complete v6: %5
Domain Authenticated: %6
Domain Probe Complete: %7

Fields #

NameDescription
InterfaceGUID GUID
InternetConnectivityv4 Boolean
InternetConnectivityv6 Boolean
InternetProbeCompletev4 Boolean
InternetProbeCompletev6 Boolean
DomainConnectivity Boolean
DomainProbeComplete Boolean

Event ID 1009: CDE reported an L2 adapter arrival.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

CDE reported an L2 adapter arrival 

 Interface: %1 

 Type: %2

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 1009,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775776,
    "time_created": "2026-05-29T16:32:57.3855017+00:00",
    "event_record_id": 107,
    "correlation": {},
    "execution": {
      "process_id": 2992,
      "thread_id": 3064
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}",
    "MediaType": "1"
  },
  "message": "CDE reported an L2 adapter arrival \r\n\r\n Interface: {2a7bd48e-ddc6-4641-9f41-682f29f1d76c} \r\n\r\n Type: Ethernet."
}

Event ID 1010: CDE reported an L2 adapter removal.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

CDE reported an L2 adapter removal 

 Interface: %1 

 Type: %2

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
    "event_source_name": "",
    "event_id": 1010,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775840,
    "time_created": "2026-03-13T20:18:51.255303+00:00",
    "event_record_id": 170,
    "correlation": {},
    "execution": {
      "process_id": 2572,
      "thread_id": 2756
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
    "MediaType": 1
  },
  "message": ""
}

Event ID 1011: CDE reported a successful connection.

#
Channel
Diagnostic
Opcode
Info

Message #

CDE reported a successful connection 

 Interface: %1 

 Type: %2

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32

Event ID 1012: CDE reported a connection failure.

#
Channel
Operational
Opcode
Info

Message #

CDE reported a connection failure 

 Interface: %1 

 Type: %2

 Status: %3

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32
Status UInt32NTSTATUS reference

Event ID 1013: CDE reported a disconnection.

#
Channel
Diagnostic
Opcode
Info

Message #

CDE reported a disconnection 

 Interface: %1 

 Type: %2

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32

Event ID 1014: WcmSetParameter Called.

#
Channel
Diagnostic
Level
Informational
Opcode
Info

Message #

WcmSetParameter Called

Interface: %1
Profile Name: %2
Wcm Opcode: %3
Data Length: %4
Caller Process ID: %5
Return Value: %6

Fields #

NameDescription
InterfaceGUID GUID
ProfileName UnicodeString
WcmOpcode UInt32
Datalength UInt32
CallerProcessID UInt32
ReturnValue UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Wcmsvc/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1014,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 3584,
      "thread_id": 12632
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Wcmsvc",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 23:51:53.357Z",
    "version": 0
  },
  "event_data": {
    "Caller Process ID": 3352,
    "Data length": 4,
    "Interface GUID": "{129E86BD-BBE0-4F5A-9644-8FBDA23B24F5}",
    "Profile Name": "NULL",
    "Return Value": 0,
    "Wcm Opcode": 304
  },
  "message": ""
}

Example keys not documented in the fields table: Caller Process ID, Data length, Interface GUID, Profile Name, Return Value, Wcm Opcode

Event ID 1015: Interface Token Applied.

#
Channel
Operational
Opcode
Info

Message #

Interface Token Applied

Interface: %1
Media Type: %2
Manual enabled: %3
Manual Filter: %4
Num Manual: %5
Manual Profiles: %6
Auto enabled: %7
Auto filter: %8
Num Auto: %9
Auto Profiles: %10

Fields #

NameDescription
InterfaceGUID
Mediatype UInt32
ManualConnect
ManualFiltercontrol
NumManualprofiles
ManualProfileNames
AutoConnect
AutoFiltercontrol
NumAutoprofiles
AutoProfileNames

Event ID 1016: Interface Token Failed.

#
Channel
Operational
Opcode
Info

Message #

Interface Token Failed

Interface: %1
Media Type: %2
Manual enabled: %3
Manual Filter: %4
Num Manual: %5
Manual Profiles: %6
Auto enabled: %7
Auto filter: %8
Num Auto: %9
AutoProfiles: %10
Status: %11

Fields #

NameDescription
InterfaceGUID
Mediatype UInt32
ManualConnect
ManualFiltercontrol
NumManualprofiles
ManualProfileNames
AutoConnect
AutoFiltercontrol
NumAutoprofiles
AutoProfileNames
Error UInt32

Event ID 1017: Soft disconnect over thresholds for interface: InterfaceGUID.

#
Channel
Operational
Opcode
Info

Message #

Soft disconnect over thresholds for interface: %1
AvgIn: %2 AvgOut: %3 SpikeIn: %4 SpikeOut: %5
Thresholds: AvgIn: %6 AvgOut: %7 SpikeIn: %8 SpikeOut:%9
All values are in bytes/second

Fields #

NameDescription
InterfaceGUID GUID
AvgIn UInt32
AvgOut UInt32
SpikeIn UInt32
SpikeOut UInt32
ThresholdAvgIn UInt32
ThresholdAvgOut UInt32
ThresholdSpikeIn UInt32
ThresholdSpikeOut UInt32

Event ID 1018: Soft disconnect under thresholds for interface: InterfaceGUID.

#
Channel
Operational
Opcode
Info

Message #

Soft disconnect under thresholds for interface: %1
AvgIn: %2 AvgOut: %3 SpikeIn: %4 SpikeOut: %5
Thresholds: AvgIn: %6 AvgOut: %7 SpikeIn: %8 SpikeOut:%9
All values are in bytes/second

Fields #

NameDescription
InterfaceGUID GUID
AvgIn UInt32
AvgOut UInt32
SpikeIn UInt32
SpikeOut UInt32
ThresholdAvgIn UInt32
ThresholdAvgOut UInt32
ThresholdSpikeIn UInt32
ThresholdSpikeOut UInt32

Event ID 1019: CDE reported an unblocked profile.

#
Channel
Operational
Opcode
Info

Message #

CDE reported an unblocked profile 

 Interface: %1 

 Type: %2

 Profile: %3

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32
ProfileName UnicodeString

Event ID 1020: WCM Preferred Order List.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

WCM Preferred Order List:
%1

Fields #

NameDescription
WCMPreferredOrderList

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
    "event_source_name": "",
    "event_id": 1020,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775840,
    "time_created": "2023-10-26T04:17:43.215170+00:00",
    "event_record_id": 9,
    "correlation": {},
    "execution": {
      "process_id": 2288,
      "thread_id": 2612
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "WCM Preferred Order List": "0: {3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}, Ethernet, 1\n1: {8E4162AD-6500-4899-BA95-24051405E207}, Ethernet, 1\n"
  },
  "message": ""
}

Example keys not documented in the fields table: WCM Preferred Order List

References #

Event ID 1022: WCM entered connected standby

#
Channel
Operational
Opcode
Info

Event ID 1023: WCM exited connected standby

#
Channel
Operational
Opcode
Info

Event ID 1024: Acquired NDIS NIC Active Reference for interface: InterfaceGUID.

#
Channel
Diagnostic
Opcode
Info

Message #

Acquired NDIS NIC Active Reference for interface: %1

Fields #

NameDescription
InterfaceGUID GUID

Event ID 1025: Released NDIS NIC Active Reference for interface: InterfaceGUID.

#
Channel
Diagnostic
Opcode
Info

Message #

Released NDIS NIC Active Reference for interface: %1

Fields #

NameDescription
InterfaceGUID GUID

Event ID 1026: CDE reported an NDIS adapter arrival.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

CDE reported an NDIS adapter arrival 

 Interface: %1 

 Type: %2

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 1026,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775776,
    "time_created": "2026-05-29T16:32:57.3851898+00:00",
    "event_record_id": 106,
    "correlation": {},
    "execution": {
      "process_id": 2992,
      "thread_id": 3064
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}",
    "MediaType": "1"
  },
  "message": "CDE reported an NDIS adapter arrival \r\n\r\n Interface: {2a7bd48e-ddc6-4641-9f41-682f29f1d76c} \r\n\r\n Type: Ethernet."
}

Event ID 1027: CDE reported an NDIS adapter removal.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

CDE reported an NDIS adapter removal 

 Interface: %1 

 Type: %2

Fields #

NameDescription
InterfaceGuid GUID
MediaType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
    "event_source_name": "",
    "event_id": 1027,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775840,
    "time_created": "2026-03-13T20:18:51.255300+00:00",
    "event_record_id": 169,
    "correlation": {},
    "execution": {
      "process_id": 2572,
      "thread_id": 2756
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
    "MediaType": 1
  },
  "message": ""
}

Event ID 1028: WCM entered net quiet mode

#
Channel
Operational
Opcode
Info

Event ID 1029: WCM exited net quiet mode

#
Channel
Operational
Opcode
Info

Event ID 1030: Billing Cycle Reset Successful

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
ProfileName UnicodeString
InterfaceGuid GUID
ProfileUpdatedorDeleted UnicodeString

Event ID 1031: Server Time Retrieval Failure

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
ConfigtoSyncWithTimeServer Boolean
TimeServerName UnicodeString
NumServerTimeRetries UInt32
ServerTimeRetrievalError UInt32

Event ID 1032: Acquire NDIS NIC Active Reference Failed for interface: InterfaceGUID.

#
Channel
Operational
Opcode
Info

Message #

Acquire NDIS NIC Active Reference Failed for interface: %1

Fields #

NameDescription
InterfaceGUID GUID
NdisRefError UInt32

Event ID 1033: Release NDIS NIC Active Reference Failed for interface: InterfaceGUID.

#
Channel
Operational
Opcode
Info

Message #

Release NDIS NIC Active Reference Failed for interface: %1

Fields #

NameDescription
InterfaceGUID GUID
NdisRefError UInt32

Event ID 1034: OnDemandInterfaceStateChanged.

#
Channel
Operational
Opcode
Info

Description

OnDemandInterfaceStateChanged. OnDemandType:OnDemandType, Interface: InterfaceGUID, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, NewState:NewState, Ref counter:Refcount.

Message #

OnDemandInterfaceStateChanged. OnDemandType:%1, Interface: %2, OnDemandInfo:%3, ProviderID:%4, NewState:%5, Ref counter:%6

Fields #

NameDescription
OnDemandType UInt32
InterfaceGUID GUID
OnDemandInfo UnicodeString
ProviderID UnicodeString
NewState UInt32
Refcount UInt32

Event ID 1035: OnDemand PDP Profile Created.

#
Channel
Diagnostic
Opcode
Info

Description

OnDemand PDP Profile Created. OnDemandInfo:APNname, ProviderID:ProviderID, SubscriberID:SubscriberID, Profile Name:Profilename.

Message #

OnDemand PDP Profile Created. OnDemandInfo:%1, ProviderID:%2, SubscriberID:%3, Profile Name:%4

Fields #

NameDescription
APNname UnicodeString
ProviderID UnicodeString
SubscriberID UnicodeString
Profilename UnicodeString

Event ID 1036: OnDemand PDP Profile Deleted.

#
Channel
Diagnostic
Opcode
Info

Description

OnDemand PDP Profile Deleted. Profile Name:Profilename.

Message #

OnDemand PDP Profile Deleted. Profile Name:%1

Fields #

NameDescription
Profilename UnicodeString

Event ID 1037: OnDemand Request opened.

#
Channel
Operational
Opcode
Info

Description

OnDemand Request opened. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.

Message #

OnDemand Request opened. App ID:%1, ProcessID:%2,OnDemandType:%3, OnDemandInfo:%4, ProviderID:%5, Error: %6

Fields #

NameDescription
AppID UnicodeString
ProcessID UInt32
OnDemandType UInt32
OnDemandInfo UnicodeString
ProviderID UnicodeString
Error UInt32

Event ID 1038: OnDemand Request closed.

#
Channel
Operational
Opcode
Info

Description

OnDemand Request closed. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.

Message #

OnDemand Request closed. App ID:%1, ProcessID:%2,OnDemandType:%3, OnDemandInfo:%4, ProviderID:%5, Error: %6

Fields #

NameDescription
AppID UnicodeString
ProcessID UInt32
OnDemandType UInt32
OnDemandInfo UnicodeString
ProviderID UnicodeString
Error UInt32

Event ID 1039: OnDemand Request started.

#
Channel
Diagnostic
Opcode
Info

Description

OnDemand Request started. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.

Message #

OnDemand Request started. App ID:%1, ProcessID:%2,OnDemandType:%3, OnDemandInfo:%4, ProviderID:%5, Error: %6

Fields #

NameDescription
AppID UnicodeString
ProcessID UInt32
OnDemandType UInt32
OnDemandInfo UnicodeString
ProviderID UnicodeString
Error UInt32

Event ID 1040: OnDemand Request cancelled.

#
Channel
Diagnostic
Opcode
Info

Description

OnDemand Request cancelled. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.

Message #

OnDemand Request cancelled. App ID:%1, ProcessID:%2,OnDemandType:%3, OnDemandInfo:%4, ProviderID:%5, Error: %6

Fields #

NameDescription
AppID UnicodeString
ProcessID UInt32
OnDemandType UInt32
OnDemandInfo UnicodeString
ProviderID UnicodeString
Error UInt32

Event ID 1050: WcmSvc acquired the NIC reference for Interface: InterfaceGUID for reason: ActionType.

#
Channel
Diagnostic
Opcode
Info

Message #

WcmSvc acquired the NIC reference for Interface: %1 for reason: %2

Fields #

NameDescription
InterfaceGUID GUID
ActionType UInt32

Event ID 1051: WcmSvc released the NIC reference for Interface: InterfaceGUID for reason: ActionType.

#
Channel
Diagnostic
Opcode
Info

Message #

WcmSvc released the NIC reference for Interface: %1 for reason: %2

Fields #

NameDescription
InterfaceGUID GUID
ActionType UInt32

Event ID 1052: WcmSvc signalled disconnected standby

#
Channel
Operational
Opcode
Info

Event ID 1053: WcmSvc signalled end of disconnected standby

#
Channel
Operational
Opcode
Info

Event ID 1054: WcmSvc received power policy update for networking in standby - the new policy value is PolicyValue.

#
Channel
Operational
Opcode
Info

Message #

WcmSvc received power policy update for networking in standby - the new policy value is %1

Fields #

NameDescription
PolicyValue UInt32

Event ID 4020: End of Wwan Resume Reconnect

#
Channel
Diagnostic
Task
MeasureWWANResumeReconnecttask
Opcode
Stop

Fields #

NameDescription
InterfaceGuid GUID

Event ID 4021: End of Wlan Resume Reconnect to Same Network

#
Channel
Diagnostic
Task
MeasureWLANResumeReconnecttask
Opcode
Stop

Fields #

NameDescription
InterfaceGuid GUID

Event ID 4022: End of Wlan Resume Reconnect to Same Network OneX

#
Channel
Diagnostic
Task
MeasureWLANResumeReconnecttask
Opcode
Stop

Fields #

NameDescription
InterfaceGuid GUID

Event ID 4023: End of Wlan Resume Reconnect to Different Network

#
Channel
Diagnostic
Task
MeasureWLANResumeReconnecttask
Opcode
Stop

Fields #

NameDescription
InterfaceGuid GUID

Event ID 4024: End of Wlan Resume Reconnect to Different Network OneX

#
Channel
Diagnostic
Task
MeasureWLANResumeReconnecttask
Opcode
Stop

Fields #

NameDescription
InterfaceGuid GUID

Event ID 4025: Cancel of Wlan Resume Reconnect2

#
Channel
Diagnostic
Task
MeasureWLANResumeReconnecttask
Opcode
Stop

Fields #

NameDescription
InterfaceGuid GUID

Event ID 4026: Measure WWAN Resume Reconnect task

#
Channel
Diagnostic
Task
MeasureWWANResumeReconnecttask
Opcode
Stop

Fields #

NameDescription
InterfaceGuid GUID

Event ID 4027: WcmSvc CmPdcActivationClientRegister - Status [Status].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc CmPdcActivationClientRegister - Status [%1]

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 4028: WcmSvc CmPdcActivationClientUnregister - Status [Status].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc CmPdcActivationClientUnregister - Status [%1]

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 4029: WcmSvc CmPdcActivationClientActivityRequest - Activate [Activity], Status [Status].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc CmPdcActivationClientActivityRequest - Activate [%1], Status [%2]

Fields #

NameDescription
Activity Boolean
Status HexInt32NTSTATUS reference

Event ID 4030: WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppNa...

#
Channel
Operational
Opcode
Info

Description

WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppName].

Message #

WcmSvc SetNetworkReference - Activate [%1], Result [%2], TotalNetworkRefCount [%3], ProcessId [%4], PerProcessNetworkRefCount [%5], App [%6]

Fields #

NameDescription
Activate Boolean
Result UInt32
TotalNetworkRefCount UInt32
ProcessId UInt32
ProcessNetworkRefCount UInt32
AppName UnicodeString

Event ID 4031: WcmSvc ReleaseNetworkReferenceInProcess - ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], TotalNetworkRefCount [TotalNetworkRefCount].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc ReleaseNetworkReferenceInProcess - ProcessId [%1], PerProcessNetworkRefCount [%2], TotalNetworkRefCount [%3]

Fields #

NameDescription
ProcessId UInt32
ProcessNetworkRefCount UInt32
TotalNetworkRefCount UInt32

Event ID 4032: WcmSvc AcquireNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc AcquireNdisReference - Result [%1], TotalCmNdisRefCount [%2], ProcessId [%3], PerProcessCmNdisRefCount [%4], App [%5]

Fields #

NameDescription
Result UInt32
TotalCmNdisRefCount UInt32
ProcessId UInt32
PerProcessCmNdisRefCount UInt32
AppName UnicodeString

Event ID 4033: WcmSvc ReleaseNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc ReleaseNdisReference - Result [%1], TotalCmNdisRefCount [%2], ProcessId [%3], PerProcessCmNdisRefCount [%4], App [%5]

Fields #

NameDescription
Result UInt32
TotalCmNdisRefCount UInt32
ProcessId UInt32
PerProcessCmNdisRefCount UInt32
AppName UnicodeString

Event ID 4034: WcmSvc ReleaseNdisReferenceInProcess - ProcessId [ProcessId], PerProcessCmNdisRefCount [ProcessNetworkRefCount], TotalCmNdisRefCount [TotalNetworkRefCount].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc ReleaseNdisReferenceInProcess - ProcessId [%1], PerProcessCmNdisRefCount [%2], TotalCmNdisRefCount [%3]

Fields #

NameDescription
ProcessId UInt32
ProcessNetworkRefCount UInt32
TotalNetworkRefCount UInt32

Event ID 4035: WcmSvc NdisReferenceError - [FunctionName]: Result [Error].

#
Channel
Operational
Opcode
Info

Message #

WcmSvc NdisReferenceError - [%1]: Result [%2]

Fields #

NameDescription
FunctionName UnicodeString
Error UInt32

Event ID 4036: CmService::NdisReference - [AcquireRelease] InterfaceLuid [InterfaceLuid], Result [Result].

#
Channel
Operational
Opcode
Info

Message #

CmService::NdisReference - [%1] InterfaceLuid [%2], Result [%3]

Fields #

NameDescription
AcquireRelease UnicodeString
InterfaceLuid UInt64
Result UInt32

Event ID 10001: WCMSVC: Start WCM Service Startup

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 10001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:57.3454710+00:00",
    "event_record_id": 105,
    "correlation": {},
    "execution": {
      "process_id": 2992,
      "thread_id": 3020
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "WCMSVC: Start WCM Service Startup"
}

Event ID 10002: WCMSVC: Complete WCM Service Startup

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 10002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:57.3868780+00:00",
    "event_record_id": 108,
    "correlation": {},
    "execution": {
      "process_id": 2992,
      "thread_id": 3020
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "WCMSVC: Complete WCM Service Startup"
}

Event ID 10003: WCMSVC: Start Service Shutdown

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 10003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:22:34.5250615+00:00",
    "event_record_id": 114,
    "correlation": {},
    "execution": {
      "process_id": 3004,
      "thread_id": 2064
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "WCMSVC: Start Service Shutdown"
}

Event ID 10004: WCMSVC: Complete Service Shutdown

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Wcmsvc",
    "guid": "{67D07935-283A-4791-8F8D-FA9117F3E6F2}",
    "event_source_name": "",
    "event_id": 10004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:22:34.5306208+00:00",
    "event_record_id": 115,
    "correlation": {},
    "execution": {
      "process_id": 3004,
      "thread_id": 2064
    },
    "channel": "Microsoft-Windows-Wcmsvc/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "WCMSVC: Complete Service Shutdown"
}

Event ID 10005: Tethering Manager Loaded Successfully

#
Channel
Diagnostic
Opcode
Info

Event ID 10006: Tethering Manager Unloaded Successfully

#
Channel
Diagnostic
Opcode
Info

Provenance

ETW provider GUID 67d07935-283a-4791-8f8d-fa9117f3e6f2

Defined in wcmsvc.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB