Microsoft-Windows-WinHttp

EventTitleChannelSampleRule
1param1.OperationalNN
2param1.OperationalNN
4loadunloadinfo.OperationalNN
9Api(ApiHandle) API called.DiagnosticNN
10Api(ApiHandle) API returned successfully.DiagnosticNN
11Api(ApiHandle) API failed with an error = Result.DiagnosticNN
12Api(ApiHandle) API pending completion.DiagnosticNN
13Api(ApiHandle) API completed.DiagnosticNN
14Api(ApiHandle) API completed with an error = Result.DiagnosticNN
100hRequest: WinHttpSetCredentials Details: Target (AuthTargets) Schemes …DiagnosticNN
801Client begins attempts to locate the WPAD configuration file: …DiagnosticNN
802Begin search for configuration file using DHCP: Interface=Interface.DiagnosticNN
803WPAD configuration file found using DHCP: Interface=Interface, …DiagnosticNN
804Search for WPAD configuration file using DHCP failed: Interface=Interface, …DiagnosticNN
805Begin search for configuration file using DNS: DetectFlags=DetectFlags.DiagnosticYN
806WPAD configuration file found using DNS: ConfigurationURL=ConfigurationURL, …DiagnosticNN
807Search for WPAD configuration file using DNS failed: DetectFlags=DetectFlags, …DiagnosticYN
808Search for WPAD configruation file failed: Error=Error.DiagnosticNN
809Begin downloading the configuration file from the configuration URL: …DiagnosticNN
810Client successfully downloaded the configuration file from the configuration …DiagnosticNN
811Downloading the configuration file from the configuration URL failed: …DiagnosticNN
812The downloaded configuration file could not be used: …DiagnosticNN
813Searching for Proxy Information for the URL: URL=URL.DiagnosticNN
814Client has successfully retrieved proxy data for accessing a specified resource: …DiagnosticNN
815Error locating proxy information for the URL: URL=URL, Error=Error.DiagnosticNN
816Blocking autoproxy determination startedDiagnosticNN
817Blocking autoproxy determination stoppedDiagnosticNN
818WinHTTP Activity Transfer EventDiagnosticNN
819AutoProxy SWPAD Decision (WPADNetworkDecision) NumConnections (NetworkCount).DiagnosticYN
820Autoproxy host IP lookup startedDiagnosticNN
821Autoproxy host IP lookup stoppedDiagnosticNN
822Autoproxy SWPAD lookup startedDiagnosticNN
823Autoproxy SWPAD lookup stoppedDiagnosticNN
824Autoproxy Detection with SWPAD ON startedDiagnosticNN
825Autoproxy Detection with SWPAD ON stoppedDiagnosticNN
826Autoproxy Detection with SWPAD UNKNOWN startedDiagnosticNN
827Autoproxy Detection with SWPAD UNKNOWN stoppedDiagnosticNN
828Autoproxy Script Download StartedDiagnosticNN
829Autoproxy Script Download StoppedDiagnosticNN
834Autoproxy full scenario startedDiagnosticYN
835Autoproxy full scenario stoppedDiagnosticYN
1051WinHTTP_GetaddrinfoStartDiagnosticYN
1052WinHTTP_GetaddrinfoStopDiagnosticYN
1053The WinHttp TLS handshake failed with version mismatch errorOperationalNN
12501The WinHTTP Web Proxy Auto-Discovery Service detected an internal data …OperationalNN
12503The WinHTTP Web Proxy Auto-Discovery Service has been idle for IdleTime minutes, …OperationalNN
12506The WinHTTP Web Proxy Auto-Discovery Service encountered a system error from …OperationalNN
12507The WinHTTP Web Proxy Auto-Discovery Service failed to allocate a critical …OperationalNN
12509The WinHTTP Web Proxy Auto-Discovery Service detected a non- local RPC request …OperationalNN
12511The WinHTTP Web Proxy Auto-Discovery Service failed to abort all pending …OperationalNN
12512The WinHTTP Web Proxy Auto-Discovery Service failed parameter validation of a …OperationalNN
12513The WinHTTP Web Proxy Auto-Discovery Service is shutting down and not accepting …OperationalNN
12514The WinHTTP Web Proxy Auto-Discovery Service detected an unexpected exception …OperationalNN
12516The WinHTTP Web Proxy Auto-Discovery Service discarded and is re-attempting a …OperationalNN
12517The WinHTTP Web Proxy Auto-Discovery Service suspended operation.OperationalNN
12518The WinHTTP Web Proxy Auto-Discovery Service resumed operation.OperationalNN
58999Message.DiagnosticNN
59995Canceling EtwQueueActionType Thread Action (Context: Context).DiagnosticYN
59996Queue EtwQueueActionType Thread Action (Context: Context).DiagnosticYN
59997Stopping EtwQueueActionType Thread Action (Context: Context).DiagnosticYN
59998Starting EtwQueueActionType Thread Action (Context: Context).DiagnosticYN
59999(File:Line) Message.DiagnosticNN

Event ID 1: param1.

#
Channel
Operational
Opcode
Info

Message #

%1

Fields #

NameDescription
param1 UnicodeString

Event ID 2: param1.

#
Channel
Operational
Opcode
Info

Message #

%1

Fields #

NameDescription
param1 UnicodeString

Event ID 4: loadunloadinfo.

#
Channel
Operational
Opcode
Info

Message #

%1

Fields #

NameDescription
loadunloadinfo UnicodeString

Event ID 9: Api(ApiHandle) API called.

#
Channel
Diagnostic
Task
API
Opcode
Start

Message #

%2(%1) API called.

Fields #

NameDescription
ApiHandle UInt64
Api AnsiString

Event ID 10: Api(ApiHandle) API returned successfully.

#
Channel
Diagnostic
Task
API
Opcode
Stop

Message #

%2(%1) API returned successfully.

Fields #

NameDescription
ApiHandle UInt64
Api AnsiString
Result UInt32

Event ID 11: Api(ApiHandle) API failed with an error = Result.

#
Channel
Diagnostic
Task
API
Opcode
Stop

Message #

%2(%1) API failed with an error = %3.

Fields #

NameDescription
ApiHandle UInt64
Api AnsiString
Result UInt32

Event ID 12: Api(ApiHandle) API pending completion.

#
Channel
Diagnostic
Task
API

Message #

%2(%1) API pending completion.

Fields #

NameDescription
ApiHandle UInt64
Api AnsiString

Event ID 13: Api(ApiHandle) API completed.

#
Channel
Diagnostic
Task
API
Opcode
Stop

Message #

%2(%1) API completed.

Fields #

NameDescription
ApiHandle UInt64
Api AnsiString
Result UInt32

Event ID 14: Api(ApiHandle) API completed with an error = Result.

#
Channel
Diagnostic
Task
API
Opcode
Stop

Message #

%2(%1) API completed with an error = %3.

Fields #

NameDescription
ApiHandle UInt64
Api AnsiString
Result UInt32

Event ID 100: hRequest: WinHttpSetCredentials Details: Target (AuthTargets) Schemes (AuthScheme) UserName (UserName) Password (Password).

#
Channel
Diagnostic
Task
API

Message #

%1: WinHttpSetCredentials Details: Target (%2) Schemes (%3) UserName (%4) Password (%5)

Fields #

NameDescription
hRequest Pointer
AuthTargets UInt32
AuthScheme UInt32
UserName UnicodeString
Password UnicodeString

Event ID 801: Client begins attempts to locate the WPAD configuration file: ConnectionName=ConnectionName, DetectFlags=DetectFlags.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_SEARCH
Opcode
Start

Message #

Client begins attempts to locate the WPAD configuration file: ConnectionName=%2, DetectFlags=%3

Fields #

NameDescription
_ConnectionNameLength UInt16
ConnectionName UnicodeString
DetectFlags UInt32

Event ID 802: Begin search for configuration file using DHCP: Interface=Interface.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DHCP
Opcode
Start

Message #

Begin search for configuration file using DHCP: Interface=%2

Fields #

NameDescription
_InterfaceLength UInt16
Interface UnicodeString

Event ID 803: WPAD configuration file found using DHCP: Interface=Interface, ConfigurationURL=ConfigurationURL.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DHCP
Opcode
Stop

Message #

WPAD configuration file found using DHCP: Interface=%2, ConfigurationURL=%4

Fields #

NameDescription
_InterfaceLength UInt16
Interface UnicodeString
_ConfigurationURLLength UInt16
ConfigurationURL UnicodeString

Event ID 804: Search for WPAD configuration file using DHCP failed: Interface=Interface, ConfigurationURL=ConfigurationURL, Error=Error.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DHCP
Opcode
Fail

Message #

Search for WPAD configuration file using DHCP failed: Interface=%2, ConfigurationURL=%4, Error=%5

Fields #

NameDescription
_InterfaceLength UInt16
Interface UnicodeString
_ConfigurationURLLength UInt16
ConfigurationURL UnicodeString
Error UInt32

Event ID 805: Begin search for configuration file using DNS: DetectFlags=DetectFlags.

#
Channel
Diagnostic
Level
Verbose
Task
WINHTTP_AUTOPROXY_DNS
Opcode
Start

Message #

Begin search for configuration file using DNS: DetectFlags=%1

Fields #

NameDescription
DetectFlags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "805",
    "version": "0",
    "level": "5",
    "task": "539",
    "opcode": "1",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-15T23:27:43.715349300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{76fd77dd-3e3d-0001-da4f-fe037c280000}"
    },
    "execution": {
      "process_id": "10364",
      "thread_id": "2964"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DetectFlags": "       3"
  },
  "message": ""
}

Event ID 806: WPAD configuration file found using DNS: ConfigurationURL=ConfigurationURL, DetectFlags=DetectFlags.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DNS
Opcode
Stop

Message #

WPAD configuration file found using DNS: ConfigurationURL=%2, DetectFlags=%3

Fields #

NameDescription
_ConfigurationURLLength UInt16
ConfigurationURL UnicodeString
DetectFlags UInt32

Event ID 807: Search for WPAD configuration file using DNS failed: DetectFlags=DetectFlags, Error=Error.

#
Channel
Diagnostic
Level
Error
Task
WINHTTP_AUTOPROXY_DNS
Opcode
Fail

Message #

Search for WPAD configuration file using DNS failed: DetectFlags=%1, Error=%2

Fields #

NameDescription
DetectFlags UInt32
Error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "807",
    "version": "0",
    "level": "2",
    "task": "539",
    "opcode": "11",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-15T23:27:43.720806000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{76fd77dd-3e3d-0001-da4f-fe037c280000}"
    },
    "execution": {
      "process_id": "10364",
      "thread_id": "2964"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "DetectFlags": "       3",
    "Error": "    1168"
  },
  "message": ""
}

Event ID 808: Search for WPAD configruation file failed: Error=Error.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_SEARCH
Opcode
Fail

Message #

Search for WPAD configruation file failed: Error=%1

Fields #

NameDescription
Error UInt32

Event ID 809: Begin downloading the configuration file from the configuration URL: ConfigurationURL=ConfigurationURL.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DOWNLOAD
Opcode
Start

Message #

Begin downloading the configuration file from the configuration URL: ConfigurationURL=%2

Fields #

NameDescription
_ConfigurationURLLength UInt16
ConfigurationURL UnicodeString

Event ID 810: Client successfully downloaded the configuration file from the configuration URL: ConfigurationURL=ConfigurationURL.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DOWNLOAD
Opcode
Stop

Message #

Client successfully downloaded the configuration file from the configuration URL: ConfigurationURL=%2

Fields #

NameDescription
_ConfigurationURLLength UInt16
ConfigurationURL UnicodeString

Event ID 811: Downloading the configuration file from the configuration URL failed: ConfigurationURL=ConfigurationURL, Error=Error.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DOWNLOAD
Opcode
Fail

Message #

Downloading the configuration file from the configuration URL failed: ConfigurationURL=%2, Error=%3

Fields #

NameDescription
_ConfigurationURLLength UInt16
ConfigurationURL UnicodeString
Error UInt32

Event ID 812: The downloaded configuration file could not be used: ConfigurationURL=ConfigurationURL, MIMEType=MIMEType, Error=Error.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_DOWNLOAD
Opcode
Fail

Message #

The downloaded configuration file could not be used: ConfigurationURL=%2, MIMEType=%4, Error=%5

Fields #

NameDescription
_ConfigurationURLLength UInt16
ConfigurationURL UnicodeString
_MIMETypeLength UInt16
MIMEType UnicodeString
Error UInt32

Event ID 813: Searching for Proxy Information for the URL: URL=URL.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_FIND_INFO_FOR_URL
Opcode
Start

Message #

Searching for Proxy Information for the URL: URL=%2

Fields #

NameDescription
_URLLength UInt16
URL UnicodeString

Event ID 814: Client has successfully retrieved proxy data for accessing a specified resource: URL=URL, ProxyString=ProxyString.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_FIND_INFO_FOR_URL
Opcode
Stop

Message #

Client has successfully retrieved proxy data for accessing a specified resource: URL=%2, ProxyString=%4

Fields #

NameDescription
_URLLength UInt16
URL UnicodeString
_ProxyStringLength UInt16
ProxyString UnicodeString

Event ID 815: Error locating proxy information for the URL: URL=URL, Error=Error.

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_FIND_INFO_FOR_URL
Opcode
Fail

Message #

Error locating proxy information for the URL: URL=%2, Error=%3

Fields #

NameDescription
_URLLength UInt16
URL UnicodeString
Error UInt32

Event ID 816: Blocking autoproxy determination started

#
Channel
Diagnostic
Task
WINHTTP_BLOCKING_AUTOPROXY_DETERMINATION
Opcode
Start

Event ID 817: Blocking autoproxy determination stopped

#
Channel
Diagnostic
Task
WINHTTP_BLOCKING_AUTOPROXY_DETERMINATION
Opcode
Stop

Event ID 818: WinHTTP Activity Transfer Event

#
Channel
Diagnostic
Task
WINHTTP_TRANSFER

Event ID 819: AutoProxy SWPAD Decision (WPADNetworkDecision) NumConnections (NetworkCount).

#
Channel
Diagnostic
Level
Informational
Task
WINHTTP_AUTOPROXY_SWPAD

Message #

AutoProxy SWPAD Decision (%1) NumConnections (%2)

Fields #

NameDescription
WPADNetworkDecision UInt32
NetworkCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "819",
    "version": "0",
    "level": "4",
    "task": "545",
    "opcode": "0",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-15T23:27:43.715279500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{76fd77dd-3e3b-0001-da4f-fe037c280000}"
    },
    "execution": {
      "process_id": "10364",
      "thread_id": "11368"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "WPADNetworkDecision": "0x0",
    "NetworkCount": "0x1"
  },
  "message": ""
}

Event ID 820: Autoproxy host IP lookup started

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_HOST_IP_LOOKUP
Opcode
Start

Event ID 821: Autoproxy host IP lookup stopped

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_HOST_IP_LOOKUP
Opcode
Stop

Event ID 822: Autoproxy SWPAD lookup started

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_SWPAD_LOOKUP
Opcode
Start

Event ID 823: Autoproxy SWPAD lookup stopped

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_SWPAD_LOOKUP
Opcode
Stop

Event ID 824: Autoproxy Detection with SWPAD ON started

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_KNOWN_DETECTION
Opcode
Start

Event ID 825: Autoproxy Detection with SWPAD ON stopped

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_KNOWN_DETECTION
Opcode
Stop

Event ID 826: Autoproxy Detection with SWPAD UNKNOWN started

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_UNKNOWN_DETECTION
Opcode
Start

Event ID 827: Autoproxy Detection with SWPAD UNKNOWN stopped

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_UNKNOWN_DETECTION
Opcode
Stop

Event ID 828: Autoproxy Script Download Started

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_SCRIPT_DOWNLOAD
Opcode
Start

Event ID 829: Autoproxy Script Download Stopped

#
Channel
Diagnostic
Task
WINHTTP_AUTOPROXY_PERFTRACK_SCRIPT_DOWNLOAD
Opcode
Stop

Event ID 834: Autoproxy full scenario started

#
Channel
Diagnostic
Level
Informational
Task
WINHTTP_AUTOPROXY_PERFTRACK_ALL
Opcode
Start

Fields #

NameDescription
UniqueId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "834",
    "version": "0",
    "level": "4",
    "task": "587",
    "opcode": "1",
    "keywords": 9223653511831486496,
    "time_created": "2026-03-15T23:26:14.408939000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{5d9553b0-0020-0000-9411-bc32b053955d}"
    },
    "execution": {
      "process_id": "4500",
      "thread_id": "12988"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "UniqueId": "       2"
  },
  "message": ""
}

Event ID 835: Autoproxy full scenario stopped

#
Channel
Diagnostic
Level
Informational
Task
WINHTTP_AUTOPROXY_PERFTRACK_ALL
Opcode
Stop

Fields #

NameDescription
UniqueId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "835",
    "version": "0",
    "level": "4",
    "task": "587",
    "opcode": "2",
    "keywords": 9223653511831486496,
    "time_created": "2026-03-15T23:26:14.409443400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{5d9553b0-0020-0000-9411-bc32b053955d}"
    },
    "execution": {
      "process_id": "4500",
      "thread_id": "12988"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "UniqueId": "       2"
  },
  "message": ""
}

Event ID 1051: WinHTTP_GetaddrinfoStart

#
Channel
Diagnostic
Level
Informational
Task
WinHTTP_Getaddrinfo
Opcode
Start

Fields #

NameDescription
Flags UInt32
AddressName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "1051",
    "version": "0",
    "level": "4",
    "task": "572",
    "opcode": "1",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-15T23:27:43.715355400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{76fd77dd-3e3d-0001-da4f-fe037c280000}"
    },
    "execution": {
      "process_id": "10364",
      "thread_id": "2964"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Flags": "0x1",
    "AddressName": "wpad"
  },
  "message": ""
}

Event ID 1052: WinHTTP_GetaddrinfoStop

#
Channel
Diagnostic
Level
Informational
Task
WinHTTP_Getaddrinfo
Opcode
Stop

Fields #

NameDescription
error UInt32
Flags UInt32
AddressName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "1052",
    "version": "0",
    "level": "4",
    "task": "572",
    "opcode": "2",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-15T23:27:43.720803100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{76fd77dd-3e3d-0001-da4f-fe037c280000}"
    },
    "execution": {
      "process_id": "10364",
      "thread_id": "2964"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "error": "   11001",
    "Flags": "0x1",
    "AddressName": "wpad"
  },
  "message": ""
}

Event ID 1053: The WinHttp TLS handshake failed with version mismatch error

#
Channel
Operational
Opcode
Info

Fields #

NameDescription
Host UnicodeString
ModulePath UnicodeString
ModuleName UnicodeString
ProcessPath UnicodeString
ProcessName UnicodeString

Event ID 12501: The WinHTTP Web Proxy Auto-Discovery Service detected an internal data corruption.

#
Channel
Operational
Opcode
Info

Event ID 12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for IdleTime minutes, it will be shut down.

#
Channel
Operational
Opcode
Info

Message #

The WinHTTP Web Proxy Auto-Discovery Service has been idle for %1 minutes, it will be shut down.

Fields #

NameDescription
IdleTime UInt32

Event ID 12506: The WinHTTP Web Proxy Auto-Discovery Service encountered a system error from Functionname: (Error Code = Errorcode) Errortext.

#
Channel
Operational
Opcode
Info

Message #

The WinHTTP Web Proxy Auto-Discovery Service encountered a system error from %1: (Error Code = %3) %2

Fields #

NameDescription
Functionname UnicodeString
Errortext UnicodeString
Errorcode UnicodeString

Event ID 12507: The WinHTTP Web Proxy Auto-Discovery Service failed to allocate a critical resource.

#
Channel
Operational
Opcode
Info

Description

The WinHTTP Web Proxy Auto-Discovery Service failed to allocate a critical resource. The system may be running low on physical memory.

Message #

The WinHTTP Web Proxy Auto-Discovery Service failed to allocate a critical resource. The system may be running low on physical memory.

Event ID 12509: The WinHTTP Web Proxy Auto-Discovery Service detected a non- local RPC request (Transport Type = Transporttype); Access Denied.

#
Channel
Operational
Opcode
Info

Description

The WinHTTP Web Proxy Auto-Discovery Service detected a non- local RPC request (Transport Type = Transporttype); Access Denied. There may have been an rogue attempt to gain access to the service through the network.

Message #

The WinHTTP Web Proxy Auto-Discovery Service detected a non- local RPC request (Transport Type = %1); Access Denied. There may have been an rogue attempt to gain access to the service through the network.

Fields #

NameDescription
Transporttype UnicodeString

Event ID 12511: The WinHTTP Web Proxy Auto-Discovery Service failed to abort all pending requests in param1 seconds.

#
Channel
Operational
Opcode
Info

Description

The WinHTTP Web Proxy Auto-Discovery Service failed to abort all pending requests in param1 seconds. The system WinHTTP Services may have been under stress and slow to respond to cancel requests.

Message #

The WinHTTP Web Proxy Auto-Discovery Service failed to abort all pending requests in %1 seconds.  The system WinHTTP Services may have been under stress and slow to respond to cancel requests.

Fields #

NameDescription
param1 UnicodeString

Event ID 12512: The WinHTTP Web Proxy Auto-Discovery Service failed parameter validation of a client request.

#
Channel
Operational
Opcode
Info

Description

The WinHTTP Web Proxy Auto-Discovery Service failed parameter validation of a client request. This may be due to an unexpected error from the system WinHTTP Services.

Message #

The WinHTTP Web Proxy Auto-Discovery Service failed parameter validation of a client request.  This may be due to an unexpected error from the system WinHTTP Services.

Event ID 12513: The WinHTTP Web Proxy Auto-Discovery Service is shutting down and not accepting client requests.

#
Channel
Operational
Opcode
Info

Event ID 12514: The WinHTTP Web Proxy Auto-Discovery Service detected an unexpected exception from the system WinHTTP Services.

#
Channel
Operational
Opcode
Info

Description

The WinHTTP Web Proxy Auto-Discovery Service detected an unexpected exception from the system WinHTTP Services. (Exception Code = Exceptioncode).

Message #

The WinHTTP Web Proxy Auto-Discovery Service detected an unexpected exception from the system WinHTTP Services. (Exception Code = %1)

Fields #

NameDescription
Exceptioncode UnicodeString

Event ID 12516: The WinHTTP Web Proxy Auto-Discovery Service discarded and is re-attempting a request after a critical power event.

#
Channel
Operational
Opcode
Info

Event ID 12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.

#
Channel
Operational
Opcode
Info

Event ID 12518: The WinHTTP Web Proxy Auto-Discovery Service resumed operation.

#
Channel
Operational
Opcode
Info

Event ID 58999: Message.

#
Channel
Diagnostic
Task
Debug

Message #

%1

Fields #

NameDescription
Message AnsiString

Event ID 59995: Canceling EtwQueueActionType Thread Action (Context: Context).

#
Channel
Diagnostic
Level
Verbose
Task
Debug
Opcode
Stop

Message #

Canceling %2 Thread Action (Context: %1)

Fields #

NameDescription
Context Pointer
EtwQueueActionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "59995",
    "version": "0",
    "level": "5",
    "task": "110",
    "opcode": "2",
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T23:26:14.409411900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{5ddbd0e0-0025-0000-9411-bc32e0d0db5d}"
    },
    "execution": {
      "process_id": "4500",
      "thread_id": "12988"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Context": "0x1CE5DDCBB20",
    "EtwQueueActionType": "       1"
  },
  "message": ""
}

Event ID 59996: Queue EtwQueueActionType Thread Action (Context: Context).

#
Channel
Diagnostic
Level
Verbose
Task
Debug
Opcode
Start

Message #

Queue %2 Thread Action (Context: %1)

Fields #

NameDescription
Context Pointer
EtwQueueActionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "59996",
    "version": "0",
    "level": "5",
    "task": "110",
    "opcode": "1",
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T23:26:14.406370000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{5d9557c0-0013-0000-9411-b828c057955d}"
    },
    "execution": {
      "process_id": "4500",
      "thread_id": "12988"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Context": "0x1CE5DE08C00",
    "EtwQueueActionType": "       2"
  },
  "message": ""
}

Event ID 59997: Stopping EtwQueueActionType Thread Action (Context: Context).

#
Channel
Diagnostic
Level
Verbose
Task
Debug
Opcode
Stop

Message #

Stopping %2 Thread Action (Context: %1)

Fields #

NameDescription
Context Pointer
EtwQueueActionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "59997",
    "version": "0",
    "level": "5",
    "task": "110",
    "opcode": "2",
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T23:26:14.406532000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{5d9557c0-0013-0000-9411-b828c057955d}"
    },
    "execution": {
      "process_id": "4500",
      "thread_id": "12988"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Context": "0x1CE5DE08C00",
    "EtwQueueActionType": "       2"
  },
  "message": ""
}

Event ID 59998: Starting EtwQueueActionType Thread Action (Context: Context).

#
Channel
Diagnostic
Level
Verbose
Task
Debug
Opcode
Start

Message #

Starting %2 Thread Action (Context: %1)

Fields #

NameDescription
Context Pointer
EtwQueueActionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinHttp",
    "guid": "{7d44233d-3055-4b9c-ba64-0d47ca40a232}",
    "event_source_name": "",
    "event_id": "59998",
    "version": "0",
    "level": "5",
    "task": "110",
    "opcode": "1",
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T23:26:14.406401200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{5d9557c0-0013-0000-9411-b828c057955d}"
    },
    "execution": {
      "process_id": "4500",
      "thread_id": "12988"
    },
    "channel": "Microsoft-Windows-WinHttp/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Context": "0x1CE5DE08C00",
    "EtwQueueActionType": "       2"
  },
  "message": ""
}

Event ID 59999: (File:Line) Message.

#
Channel
Diagnostic
Task
Debug

Message #

(%1:%2) %4

Fields #

NameDescription
File AnsiString
Line UInt32
Length UInt16
Message AnsiString

Provenance

ETW provider GUID 7d44233d-3055-4b9c-ba64-0d47ca40a232

Defined in winhttp.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB