Microsoft-Windows-WinRM

EventTitleChannelSampleRule
2Initializing WSMan APIOperationalYN
3Initialization of WSMan API failed, error code errorCode.OperationalNN
4Deinitializing WSMan APIOperationalYN
5Deinitialization of WSMan API failed, error code errorCode.OperationalNN
6Creating WSMan Session.OperationalYN
7WSMan Create Session operation failed, error code errorCode.OperationalNN
8Closing WSMan SessionOperationalYN
9Closing WSMan Session failed, error code errorCode.OperationalNN
10Setting WSMan Session Option (optionCode) - optionName with value (optionValue) …OperationalYN
11Creating WSMan shell with the ResourceUri: resourceUri and ShellId: shellId.OperationalYN
12WSMan shell creation failed, error code errorCode.OperationalYN
13Running WSMan command with CommandId: commandId.OperationalYN
14Running WSMan command failed, error code errorCode.OperationalNN
15Closing WSMan commandOperationalYN
16Closing WSMan shellOperationalYN
17Signaling WSMan shellOperationalNN
18Signaling WSMan shell; error code {errorCode}.OperationalNN
19Closing WSMan operationOperationalNN
20Sending input to the shellOperationalNN
21Sending input operation failed; error code {errorCode}.OperationalNN
22Calling into WSMan to receive output from the shellOperationalNN
23WSMan receive operation failed; error code {errorCode}.OperationalNN
24Calling into WSMan to receive output from the commandOperationalNN
26Getting message for error code {inputErrorCode} completed successfully.OperationalNN
27Getting WSMan Session Option ({optionCode}).OperationalNN
28Access Denied error: the apiCall API caller does not match the creator of the …OperationalNN
29Initialization of WSMan API completed successfulyOperationalYN
30Deinitialization of WSMan API completed successfulyOperationalYN
31WSMan Create Session operation completed successfulyOperationalYN
32Setting WSMan Session Option (optionCode) - optionName failed, error code …OperationalNN
33Closing WSMan Session completed successfulyOperationalYN
34Getting message for error code {inputErrorCode} failed; the resulting error code …OperationalNN
35Signaling WSMan command failed; error code {errorCode}.OperationalNN
36Signaling WSMan commandOperationalNN
37Closing WSMan shell failed, error code errorCode.OperationalNN
38Closing WSMan command failed, error code errorCode.OperationalNN
39Closing WSMan {operationName} operation completed successfully.OperationalNN
40Closing WSMan operationName operation failed, error code errorCode.OperationalNN
41The WinRM protocol handler has began loading for application applicationID.OperationalYN
42The WinRM protocol handler completed unloading.OperationalYN
43The WinRM protocol handler unloaded prematurely due to the following error: …OperationalNN
44The WinRM protocol handler started to create a session at the following …OperationalYN
45The WinRM protocol handler closed the session.OperationalYN
46The WinRM protocol session closed prematurely due to the following error: …OperationalNN
47The WinRM protocol session began an operation of type operationType to the …OperationalYN
48The WinRM protocol session successfully completed the operation.OperationalYN
49The WinRM protocol operation failed due to the following error: errorMessage.OperationalYN
64Auto-detecting proxy settingsOperationalNN
65Proxy AutoDetect done.OperationalNN
66Setting proxy info Proxy list: {proxyList} Bypass list: {bypassList}.OperationalNN
80Sending the request for operation {operationName} to destination machine and …OperationalNN
81Processing client request for operation {operationName}.OperationalNN
82Entering the plugin for operation {operation} with a ResourceURI of …OperationalNN
83Leaving the plugin for operation {operation}.OperationalNN
84The maximum number of users (users) executing shell operations has been …OperationalNN
85The senderName user is allowed a maximum number of concurrentShells concurrent …OperationalNN
86The WSMan service could not launch a host process to process the given request.OperationalYN
87The WSMan host process was unexpectedly terminated.OperationalYN
90RunAs was disabled by Group Policy; WSMan service has erased all RunAs …OperationalNN
91Creating WSMan shell on server with ResourceUri: resourceUri.OperationalYN
129Received the response from Network layer; status: {status}.OperationalNN
130Received the response from Network layer; status: {status}.OperationalNN
131Received redirect status code from Network layer; status: 302 …OperationalNN
132WSMan operation operationName completed successfully.OperationalYN
133Sending response error packet for ActionURI: {actionUri}.OperationalNN
134Sending response for operation {operationName}.OperationalNN
135Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT, using next …OperationalNN
136Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED, using …OperationalNN
137Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot …OperationalNN
138The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)OperationalYN
139The client got a login failure from the network layer …OperationalNN
140Sending HTTP error back to the client due to a transport failure.OperationalNN
141Sending timeout response for operation: {operationName}.OperationalNN
142WSMan operation operationName failed, error code errorCode.OperationalYN
143Received the response from Network layer; status: 200 (HTTP_STATUS_OK)OperationalNN
145WSMan operation operationName started with resourceUri resourceUri.OperationalYN
160Authenticating the user using {authentication} mechanism.OperationalNN
161authFailureMessage.OperationalYN
162Authenticating the user failed.OperationalYN
163The authentication mechanism (authClient) requested by the client is not …OperationalNN
164The destination computer (destinationMachine) returned an 'access denied' error.OperationalNN
165The authentication mechanism requested by the proxy is not supported by the …OperationalNN
166The chosen authentication mechanism is {auth}.OperationalNN
168Sending HTTP 401 response to the client and disconnect the connection after …OperationalNN
169Event ID 169OperationalYN
170The authentication using client certificate with subject {subject} done …OperationalNN
171Authenticating the user with the proxy failed.OperationalNN
172The server certificate on the destination computer (machineName:port) has the …OperationalNN
173The WinRM service has terminated param1 unauthenticated connections over the …OperationalNN
192The authorization of the user failed with error errorCode.OperationalYN
193Request for user param1 (param2) will be executed using WinRM virtual account …OperationalYN
194The authorization of the user failed with error {errorCode}.OperationalNN
208The Winrm service is startingOperationalYN
209The Winrm service started successfullyOperationalYN
210The WinRM service is unable to start because of a failure during initialization.OperationalNN
211The Winrm service is stoppingOperationalYN
212The Winrm service was stopped successfullyOperationalYN
213The WSMan service could not load current configuration settings as the settings …OperationalNN
214The WSMan client could not load current configuration settings as the settings …OperationalNN
215The WSMan service failed to read configuration of the following plugin.OperationalNN
216The WSMan service failed to restart the plugins marked for AutoRestart.OperationalNN
217The WSMan service failed to restart the pluginName plugin on service startup.OperationalNN
218The WSMan service successfully restarted the following plugin on service …OperationalNN
219The WSMan shell instance param1 will no longer support disconnect reconnect …OperationalNN
224message.OperationalYN
229The WinRM param1 failed to register for group policy change notifications.OperationalNN
230Deletion of registry key param1 resulted in access denied.OperationalNN
254Activity TransferOperationalYN
255Activity TransferAnalyticYN
257Initializing WSMan APIAnalyticNN
258Initialization of WSMan API failed; error code {errorCode}.AnalyticNN
259Deinitializing WSMan APIAnalyticNN
260Deinitialization of WSMan API failed; error code {errorCode}.AnalyticNN
261Creating WSMan Session.AnalyticNN
262WSMan Create Session operation failed; error code {errorCode}.AnalyticNN
263Closing WSMan SessionAnalyticNN
264Closing WSMan Session failed; error code {errorCode}.AnalyticNN
265Setting WSMan Session Option ({optionCode}) with value ({optionValue}) completed …AnalyticNN
266Creating WSMan shell with the ResourceUri: {resourceUri}.AnalyticNN
267WSMan shell creation failed; error code {errorCode}.AnalyticNN
268Running WSMan commandAnalyticNN
269Running WSMan command failed; error code {errorCode}.AnalyticNN
270Closing WSMan commandAnalyticNN
271Closing WSMan shellAnalyticNN
272Signaling WSMan shellAnalyticNN
273Signaling WSMan shell; error code {errorCode}.AnalyticNN
274Closing WSMan operationAnalyticNN
275Sending input to the shellAnalyticNN
276Sending input operation failed; error code {errorCode}.AnalyticNN
277Calling into WSMan to receive output from the shellAnalyticNN
278WSMan receive operation failed; error code {errorCode}.AnalyticNN
279Calling into WSMan to receive output from the commandAnalyticNN
280Getting message for error code {inputErrorCode} completed successfully.AnalyticNN
281Getting WSMan Session Option ({optionCode}).AnalyticNN
282Access Denied error: the {apiCall} API caller does not match the creator of the …AnalyticNN
283Plug-in reporting context for operation operationName.AnalyticYN
284Plug-in reporting data object for operation operationName.AnalyticNN
285Plug-in reporting data object and EPR for operation operationName.AnalyticNN
286Plug-in reporting data object and bookmark for operation operationName.AnalyticNN
287Plug-in reporting data for operation ReceiveAnalyticYN
288Plug-in reporting operation complete for operationName.AnalyticYN
289Plug-in getting operational information for parameter parameters and operation …AnalyticYN
290Plug-in reporting the authorization for user username completed with error code …AnalyticNN
291Plug-in reporting the authorization operation completed with error errorCode for …AnalyticNN
292Updating the quota for the user username with error code errorCode.AnalyticYN
293Initialization of WSMan API completed successfulyAnalyticNN
294Deinitialization of WSMan API completed successfulyAnalyticNN
295WSMan Create Session operation completed successfulyAnalyticNN
296Setting WSMan Session Option ({optionCode}) failed; error code {errorCode}.AnalyticNN
297Closing WSMan Session completed successfulyAnalyticNN
298Getting message for error code {inputErrorCode} failed; the resulting error code …AnalyticNN
299Signaling WSMan command failed; error code {errorCode}.AnalyticNN
300Signaling WSMan commandAnalyticNN
301Closing WSMan shell failed; error code {errorCode}.AnalyticNN
302Closing WSMan command failed; error code {errorCode}.AnalyticNN
303Closing WSMan {operationName} operation completed successfully.AnalyticNN
304Closing WSMan {operationName} operation failed; error code {errorCode}.AnalyticNN
305Sending input to the commandAnalyticNN
306The WinRM service loaded the following plugin: provider (path).AnalyticYN
307The WinRM service unloaded the following plugin: provider (path).AnalyticYN
308The plugin called WSManPluginGetConfiguration with the parameter Flags and …AnalyticNN
309The plugin called WSManPluginReportCompletion with the parameter Flags and …AnalyticNN
310The plugin Plugin is being shut down because it was idle for longer than the …AnalyticNN
311Signaling WSMan command failed, error code errorCode.AnalyticNN
312Signaling WSMan commandAnalyticNN
313Sending input to the commandAnalyticNN
314Sending input to the shellAnalyticNN
315Sending input operation failed, error code errorCode.AnalyticNN
316Calling into WSMan to receive output from the shellAnalyticYN
317WSMan receive operation failed, error code errorCode.AnalyticNN
318Calling into WSMan to receive output from the commandAnalyticYN
319Getting message for error code inputErrorCode completed successfully.AnalyticYN
320Getting WSMan Session Option (optionCode) - optionName.AnalyticYN
321Signaling WSMan shellAnalyticNN
322Signaling WSMan shell, error code errorCode.AnalyticNN
323Closing WSMan operationAnalyticYN
324Closing WSMan operationName operation completed successfully.AnalyticYN
325Disconnecting shell with Id : argument.AnalyticNN
326Disconnecting shell failed, error code errorCode.AnalyticNN
327Reconnecting shell with Id : argument.AnalyticNN
328Reconnecting shell failed, error code errorCode.AnalyticNN
329Connecting shell with Id : argument.AnalyticNN
330Connecting shell failed, error code errorCode.AnalyticNN
331Reconnecting shell command with Id : argument.AnalyticNN
332Reconnecting shell command failed, error code errorCode.AnalyticNN
333Connecting shell command with Id : argument.AnalyticNN
334Connecting shell command failed, error code errorCode.AnalyticNN
512Auto-detecting proxy settingsAnalyticNN
513Proxy AutoDetect done.AnalyticNN
514Setting proxy info.AnalyticNN
768Processing client request for operation {operationName}.AnalyticNN
769Entering the plugin for operation {operation} with a ResourceURI of …AnalyticNN
770Leaving the plugin for operation {operation}.AnalyticNN
771SOAP [client sending index index of totalChunks total chunks (bytes bytes)] …AnalyticNN
772SOAP [listener receiving index index of totalChunks total chunks (bytes bytes)] …AnalyticYN
773The {senderName} user is allowed a maximum number of {concurrentShells} …AnalyticNN
774The senderName user is allowed a maximum number of concurrentOperations …AnalyticNN
775The user load quota of requests requests per windowTime seconds has been …AnalyticNN
776The system load quota of requests requests per windowTime seconds has been …AnalyticNN
777The maximum number of users ({users}) executing shell operations has been …AnalyticNN
778Sending the request for operation {operationName} to destination machine and …AnalyticNN
779SOAP [client sending index index of totalChunks total chunks (bytes bytes)] …AnalyticYN
780The WinRM param1 has encountered network connectivity issues.AnalyticNN
781The WinRM Client is attempting to re-establish a network connection.AnalyticNN
782The WinRM Service has detected a new network connection from the client.AnalyticNN
783The WinRM param1 has successfully re-established a network connection.AnalyticNN
784The WinRM param1 failed to re-establish a network connection and is reporting a …AnalyticNN
785The WSMan host process was started for user userName.AnalyticYN
786The WSMan host process was terminated for user userName.AnalyticYN
787Sending the request for operation operationName to destination machine and port …AnalyticYN
788Processing client request for operation operationName.AnalyticYN
789Entering the plugin for operation operation with a ResourceURI of <resourceURI>.AnalyticYN
790Leaving the plugin for operation operation.AnalyticYN
791The WinRM service failed to enumerate DASH/SMASH specifications with MI error: …AnalyticNN
1024Sending response for operation {operationName}.AnalyticNN
1025Sending response error packet for ActionURI: actionUri.AnalyticNN
1026SOAP [client receiving index index of totalChunks total chunks (bytes bytes)] …AnalyticYN
1027SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] …AnalyticNN
1028Received the response from Network layer; status: {status}.AnalyticNN
1029Received the response from Network layer; status: {status}.AnalyticNN
1030Received redirect status code from Network layer; status: 302 …AnalyticNN
1031WSMan operation {operationName} completed successfully.AnalyticNN
1032Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT; using next …AnalyticNN
1033Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED; using …AnalyticNN
1034Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot …AnalyticNN
1035The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)AnalyticNN
1036The client got a login failure from the network layer …AnalyticNN
1037The WSMan service could not launch a host process to process the given request.AnalyticNN
1038The WSMan host process was unexpectedly terminated.AnalyticNN
1039Sending HTTP error back to the client due to a transport failure.AnalyticNN
1040Sending timeout response for operation: {operationName}.AnalyticNN
1041Enumeration is shutting downAnalyticNN
1042WSMan operation {operationName} failed; error code {errorCode}.AnalyticNN
1043Subscription is shutting downAnalyticNN
1044SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] …AnalyticYN
1045Received the response from Network layer; status: 200 (HTTP_STATUS_OK)AnalyticYN
1046An extended semantics callback timed out for the operationName operation.AnalyticNN
1047Received the response from Network layer; status: status.AnalyticYN
1048Sending HTTP error back to the client due to a transport failure.AnalyticNN
1049Sending timeout response for operation: operationName.AnalyticNN
1050Sending response for operation operationName.AnalyticYN
1051Received the response from Network layer; status: status.AnalyticNN
1052WSMan operation operationName completed successfully.AnalyticYN
1053WSMan operation operationName got suspended because of WSMan Shell …AnalyticNN
1054WSMan operation operationName resuming because of WSMan Shell reconnection.AnalyticNN
1280Sending HTTP 401 response to the client and disconnect the connection after …AnalyticNN
1281User {username} authenticated successfully using {authenticationMechanism} …AnalyticNN
1282The authentication using client certificate with subject {subject} done …AnalyticNN
1283Authenticating the user using {authentication} mechanism.AnalyticNN
1285Authenticating the user failed.AnalyticNN
1286The authentication mechanism ({authClient}) requested by the client is not …AnalyticNN
1287The destination computer ({destinationMachine}) returned an 'access denied' …AnalyticNN
1288The authentication mechanism requested by the proxy is not supported by the …AnalyticNN
1289The chosen authentication mechanism is {auth}.AnalyticNN
1291Network layer AutoLogon policy was set to Low as a result of a HTTP 401 response …AnalyticNN
1292Network layer AutoLogon policy was set to HighAnalyticNN
1293The chosen authentication mechanism is auth.AnalyticYN
1294Sending HTTP 401 response to the client and disconnect the connection after …AnalyticYN
1295User username authenticated successfully using authenticationMechanism …AnalyticYN
1296The authentication using client certificate with subject subject done …AnalyticNN
1297Authenticating the user using authentication mechanism.AnalyticNN
1536Authorizing the userAnalyticYN
1537The authorization of the user was done successfullyAnalyticYN
1538The authorization of the user failed with error {errorCode}.AnalyticNN
1792The Winrm service is startingAnalyticNN
1793The Winrm service started successfullyAnalyticNN
1794The WinRM service is unable to start because of a failure during initialization.AnalyticNN
1795The Winrm service is stoppingAnalyticNN
1796The Winrm service was stopped successfullyAnalyticNN
1797The WSMan service could not load current configuration settings as the settings …AnalyticNN
1798The WSMan client could not load current configuration settings as the settings …AnalyticNN
1799The WSMan service failed to read configuration of the following plugin: …AnalyticNN
1808Event ID 1808AnalyticNN
1840An error was encountered while processing an operation.AnalyticYN
1841An error was encountered while processing an operation.AnalyticNN
1842Extra information.AnalyticNN
1843An unauthenticated connection from client clientIP is terminated.AnalyticNN
2048[Filename:- param1; Line:- param2; Function:- param3;] param4.DebugNN
2049[Filename:- param1; Line:- param2; Function:- param3; ErrorCode:- param4] …DebugNN
10111User authentication using Basic authentication scheme failed.SystemYN
10148The WinRM service is listening for WS-Management requestsSystemYN
10149The WinRM service is not listening for WS-Management requestsSystemYN
10154The WinRM service failed to create the following SPNs: spn1;SystemYN
468853The WinRM service is not listening for requests since it failed to listen on at …OperationalNN
468854The WinRM service is not listening for param1 requests because there was a …OperationalNN
468855The WS-Management client is not listening for pushed events because there was a …OperationalNN
468856The WinRM service is not listening for HTTPS requests because there was a …OperationalNN
468857The WS-Management client is not listening for pushed events because there was a …OperationalNN
468862The WinRM service cannot validate the client certificate because the revocation …OperationalNN
468863User authentication using Basic authentication scheme failed.OperationalNN
468864The client certificate exceeded the maximum size allowed by the WinRM service.OperationalNN
468865Request processing failed because the WinRM service cannot load data or event …OperationalNN
468866The SSL configuration for IP param1 and port param2 is shared with another …OperationalNN
468871The WinRM service is unable to start because of a failure during initialization.OperationalNN
468872The WinRM service has received an unsecure HTTP connection from param1.OperationalNN
468873The WinRM service has been configured to accept basic authentication for …OperationalNN
468880The WinRM service is not listening for HTTP requests because there was a failure …OperationalNN
468881The WS-Management client is not listening for pushed events because there was a …OperationalNN
468882IP Filter param1 specified in the GPO policy for Auto Configuration of listeners …OperationalNN
468883The IP Range param1 is invalid and it will be ignored.OperationalNN
468884The WinRM service is not listening for policy changes because there was a …OperationalNN
468888The WinRM service encountered a catastrophic security failure.OperationalNN
468889The WinRM service cannot migrate the listener with IP address param1 and Port …OperationalNN
468890The WinRM service cannot migrate the listener with Address param1 and Transport …OperationalNN
468891The WinRM service cannot migrate the listener with IP address param1 and Port …OperationalNN
468892The WinRM service cannot migrate the listener with Address param1 and Transport …OperationalNN
468893The WinRM service cannot migrate the listener with IP address param1, Port …OperationalNN
468894The WinRM service cannot migrate the listener with Address param1 and Transport …OperationalNN
468895The WinRM service had a failure during migration.OperationalNN
468896The WinRM service had a failure reading the current configuration and is …OperationalNN
468897The WinRM service had a failure applying the current configuration and is …OperationalNN
468898The WinRM service had a failure reading the current configuration and is …OperationalNN
468899The host name pattern "param1" is invalid and it will be ignored.OperationalNN
468900The WinRM service is listening for WS-Management requests.OperationalYN
468901The WinRM service is not listening for WS-Management requests.OperationalYN
468902The WinRM service could not use the following listener to receive WS-Management …OperationalNN
468903The WinRM service had a failure (param1) reading configuration during ip address …OperationalNN
468904The WinRM service successfully processed an address change notification.OperationalNN
468905The WSMan IIS module failed to read configuration.OperationalNN
468906The WinRM service failed to create the following SPNs: spn1; spn2.OperationalYN
468907The WSMan service failed to read configuration of the following plugin.OperationalNN
468908The WinRM service failed to initialize CredSSP.OperationalNN
468909The WinRM service received an error while trying to unloading a data or event …OperationalNN
468910The WinRM service is listening on the default param1 port param2 and on param1 …OperationalNN
468911The WinRM service has terminated param1 unauthenticated connections over the …OperationalNN
3221734403The WinRM service is stopping because there was a failure registering for …OperationalNN
3221734404The WinRM service is stopping because there was a failure registering for …OperationalNN

Event ID 2: Initializing WSMan API

#
Channel
Operational
Level
Informational
Task
WSManAPIInitialize
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.458003+00:00",
    "event_record_id": 96,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 3: Initialization of WSMan API failed, error code errorCode.

#
Channel
Operational
Task
WSManAPIInitialize
Opcode
Stop

Message #

Initialization of WSMan API failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 4: Deinitializing WSMan API

#
Channel
Operational
Level
Informational
Task
WSManAPIDeinitialize
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.792427+00:00",
    "event_record_id": 379,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5972
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 5: Deinitialization of WSMan API failed, error code errorCode.

#
Channel
Operational
Task
WSManAPIDeinitialize
Opcode
Stop

Message #

Deinitialization of WSMan API failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 6: Creating WSMan Session.

#
Channel
Operational
Level
Informational
Task
WSManSessioninitialize
Opcode
Start

Description

Creating WSMan Session. The connection string is: connection.

Message #

Creating WSMan Session. The connection string is: %1

Fields #

NameDescription
connection UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 6,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.465878+00:00",
    "event_record_id": 98,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "connection": "localhost:47001/WSMan?MSP=7a83d074-bb86-4e52-aa3e-6cc73cc066c8;PSVersion=5.1.20348.617"
  },
  "message": ""
}

References #

Event ID 7: WSMan Create Session operation failed, error code errorCode.

#
Channel
Operational
Task
WSManSessioninitialize
Opcode
Stop

Message #

WSMan Create Session operation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 8: Closing WSMan Session

#
Channel
Operational
Level
Informational
Task
WSManSessiondeinitialize
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 8,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.790604+00:00",
    "event_record_id": 378,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5944
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 9: Closing WSMan Session failed, error code errorCode.

#
Channel
Operational
Task
WSManSessiondeinitialize
Opcode
Stop

Message #

Closing WSMan Session failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 10: Setting WSMan Session Option (optionCode) - optionName with value (optionValue) completed successfully.

#
Channel
Operational
Level
Informational
Task
WSManAPIcall

Message #

Setting WSMan Session Option (%1) - %2 with value (%3) completed successfully.

Fields #

NameDescription
optionCode UInt32
optionName UnicodeString
optionValue UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 10,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.476896+00:00",
    "event_record_id": 106,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "optionCode": 16,
    "optionName": "WSMAN_OPTION_TIMEOUTMS_SIGNAL_SHELL",
    "optionValue": "60000"
  },
  "message": ""
}

References #

Event ID 11: Creating WSMan shell with the ResourceUri: resourceUri and ShellId: shellId.

#
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Message #

Creating WSMan shell with the ResourceUri: %1 and ShellId: %2

Fields #

NameDescription
resourceUri UnicodeString
shellId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 11,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.628784+00:00",
    "event_record_id": 107,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "resourceUri": "http://schemas.microsoft.com/powershell/Microsoft.Windows.ServerManagerWorkflows",
    "shellId": "1480B89F-E871-42E4-BFB4-C8F88B053137"
  },
  "message": ""
}

References #

Event ID 12: WSMan shell creation failed, error code errorCode.

#
Channel
Operational
Level
Error
Task
WSManAPIcall
Opcode
Stop

Message #

WSMan shell creation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 12,
    "version": 0,
    "level": 2,
    "task": 5,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T19:30:27.006555+00:00",
    "event_record_id": 14808,
    "correlation": {
      "ActivityID": "FAA0C715-5567-44CF-A321-805CC6FC7AE4"
    },
    "execution": {
      "process_id": 4488,
      "thread_id": 4272
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "errorCode": 2150859195
  },
  "message": ""
}

Event ID 13: Running WSMan command with CommandId: commandId.

#
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Message #

Running WSMan command with CommandId: %1

Fields #

NameDescription
commandId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 13,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:40.298938+00:00",
    "event_record_id": 111,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4100
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "commandId": "69F6EC7D-1A5C-485B-B375-C500E469097C"
  },
  "message": ""
}

References #

Event ID 14: Running WSMan command failed, error code errorCode.

#
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Message #

Running WSMan command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 15: Closing WSMan command

#
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 15,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:43.025520+00:00",
    "event_record_id": 112,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 940
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 16: Closing WSMan shell

#
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 16,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T08:14:07.049150+00:00",
    "event_record_id": 63,
    "correlation": {
      "ActivityID": "DD7B0B6A-4A9E-0001-93A4-7BDD9E4AD801"
    },
    "execution": {
      "process_id": 1460,
      "thread_id": 3116
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 17: Signaling WSMan shell

#
Channel
Operational

Event ID 18: Signaling WSMan shell; error code {errorCode}.

#
Channel
Operational

Fields #

NameDescription
errorCode

Event ID 19: Closing WSMan operation

#
Channel
Operational

Event ID 20: Sending input to the shell

#
Channel
Operational

Event ID 21: Sending input operation failed; error code {errorCode}.

#
Channel
Operational

Fields #

NameDescription
errorCode

Event ID 22: Calling into WSMan to receive output from the shell

#
Channel
Operational

Event ID 23: WSMan receive operation failed; error code {errorCode}.

#
Channel
Operational

Fields #

NameDescription
errorCode

Event ID 24: Calling into WSMan to receive output from the command

#
Channel
Operational

Event ID 26: Getting message for error code {inputErrorCode} completed successfully.

#
Channel
Operational

Description

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}.

Message #

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}

Fields #

NameDescription
inputErrorCode
languageCode

Event ID 27: Getting WSMan Session Option ({optionCode}).

#
Channel
Operational

Fields #

NameDescription
optionCode

Event ID 28: Access Denied error: the apiCall API caller does not match the creator of the application object.

#
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Message #

Access Denied error: the %1 API caller does not match the creator of the application object

Fields #

NameDescription
apiCall UnicodeString

Event ID 29: Initialization of WSMan API completed successfuly

#
Channel
Operational
Level
Informational
Task
WSManAPIInitialize
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 29,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.458595+00:00",
    "event_record_id": 97,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 30: Deinitialization of WSMan API completed successfuly

#
Channel
Operational
Level
Informational
Task
WSManAPIDeinitialize
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 30,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.857484+00:00",
    "event_record_id": 396,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5972
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 31: WSMan Create Session operation completed successfuly

#
Channel
Operational
Level
Informational
Task
WSManSessioninitialize
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 31,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.472808+00:00",
    "event_record_id": 99,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 32: Setting WSMan Session Option (optionCode) - optionName failed, error code errorCode.

#
Channel
Operational
Task
WSManAPIcall

Message #

Setting WSMan Session Option (%1) - %2 failed, error code %3.

Fields #

NameDescription
optionCode UInt32
optionName UnicodeString
errorCode UInt32

Event ID 33: Closing WSMan Session completed successfuly

#
Channel
Operational
Level
Informational
Task
WSManSessiondeinitialize
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 33,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.857495+00:00",
    "event_record_id": 397,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5944
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 34: Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}.

#
Channel
Operational

Fields #

NameDescription
inputErrorCode
errorCode

Event ID 35: Signaling WSMan command failed; error code {errorCode}.

#
Channel
Operational

Fields #

NameDescription
errorCode

Event ID 36: Signaling WSMan command

#
Channel
Operational

Event ID 37: Closing WSMan shell failed, error code errorCode.

#
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Message #

Closing WSMan shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 38: Closing WSMan command failed, error code errorCode.

#
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Message #

Closing WSMan command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 39: Closing WSMan {operationName} operation completed successfully.

#
Channel
Operational

Fields #

NameDescription
operationName

Event ID 40: Closing WSMan operationName operation failed, error code errorCode.

#
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Message #

Closing WSMan %1 operation failed, error code %2

Fields #

NameDescription
operationName UnicodeString
errorCode UInt32

Event ID 41: The WinRM protocol handler has began loading for application applicationID.

#
Channel
Operational
Level
Informational
Task
WinRMMIProtocolHandler
Opcode
Start

Message #

The WinRM protocol handler has began loading for application %1.

Fields #

NameDescription
applicationID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 41,
    "version": 0,
    "level": 4,
    "task": 14,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:54.064765+00:00",
    "event_record_id": 113,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "applicationID": "ServerManager.exe"
  },
  "message": ""
}

References #

Event ID 42: The WinRM protocol handler completed unloading.

#
Channel
Operational
Level
Informational
Task
WinRMMIProtocolHandler
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 42,
    "version": 0,
    "level": 4,
    "task": 14,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T16:57:49.982619+00:00",
    "event_record_id": 1760,
    "correlation": {
      "ActivityID": "028C3802-AD9E-000D-4C43-8D029EADDC01"
    },
    "execution": {
      "process_id": 8788,
      "thread_id": 10176
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 43: The WinRM protocol handler unloaded prematurely due to the following error: errorMessage.

#
Channel
Operational
Task
WinRMMIProtocolHandler
Opcode
Stop

Message #

The WinRM protocol handler unloaded prematurely due to the following error: %2.

Fields #

NameDescription
errorCode UInt32
errorMessage UnicodeString

Event ID 44: The WinRM protocol handler started to create a session at the following destination: destination.

#
Channel
Operational
Level
Informational
Task
WinRMMISession
Opcode
Start

Message #

The WinRM protocol handler started to create a session at the following destination: %1.

Fields #

NameDescription
destination UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 44,
    "version": 0,
    "level": 4,
    "task": 15,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.208888+00:00",
    "event_record_id": 276,
    "correlation": {},
    "execution": {
      "process_id": 4444,
      "thread_id": 2008
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "destination": "<local>"
  },
  "message": ""
}

References #

Event ID 45: The WinRM protocol handler closed the session.

#
Channel
Operational
Level
Informational
Task
WinRMMISession
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 45,
    "version": 0,
    "level": 4,
    "task": 15,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.283057+00:00",
    "event_record_id": 283,
    "correlation": {},
    "execution": {
      "process_id": 4444,
      "thread_id": 4432
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 46: The WinRM protocol session closed prematurely due to the following error: errorMessage.

#
Channel
Operational
Task
WinRMMISession
Opcode
Stop

Message #

The WinRM protocol session closed prematurely due to the following error: %2.

Fields #

NameDescription
errorCode UInt32
errorMessage UnicodeString

Event ID 47: The WinRM protocol session began an operation of type operationType to the server.

#
Channel
Operational
Level
Informational
Task
WinRMMIOperation
Opcode
Start

Description

The WinRM protocol session began an operation of type operationType to the server. The operation accesses class className under the namespaceName namespace.

Message #

The WinRM protocol session began an operation of type %1 to the server. The operation accesses class %3 under the %2 namespace.

Fields #

NameDescription
operationType UnicodeString
namespaceName UnicodeString
className UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 47,
    "version": 0,
    "level": 4,
    "task": 16,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.268345+00:00",
    "event_record_id": 278,
    "correlation": {
      "ActivityID": "E0AAB88C-4A9F-0001-B210-ABE09F4AD801"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4432
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "operationType": "GetClass",
    "namespaceName": "root/microsoft/windows/smb",
    "className": "MSFT_SmbServerConfiguration"
  },
  "message": ""
}

References #

Event ID 48: The WinRM protocol session successfully completed the operation.

#
Channel
Operational
Level
Informational
Task
WinRMMIOperation
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 48,
    "version": 0,
    "level": 4,
    "task": 16,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.278922+00:00",
    "event_record_id": 281,
    "correlation": {
      "ActivityID": "E0AAB88C-4A9F-0001-B210-ABE09F4AD801"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4432
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 49: The WinRM protocol operation failed due to the following error: errorMessage.

#
Channel
Operational
Level
Error
Task
WinRMMIOperation
Opcode
Stop

Message #

The WinRM protocol operation failed due to the following error: %2.

Fields #

NameDescription
errorCode UInt32
errorMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 49,
    "version": 0,
    "level": 2,
    "task": 16,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T16:57:49.042601+00:00",
    "event_record_id": 1757,
    "correlation": {
      "ActivityID": "028C3802-AD9E-000D-4C43-8D029EADDC01"
    },
    "execution": {
      "process_id": 8788,
      "thread_id": 9388
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "errorCode": 2150859195,
    "errorMessage": "The WinRM client cannot process the request. Default authentication may be used with an IP address under the following conditions: the transport is HTTPS or the destination is in the TrustedHosts list, and explicit credentials are provided. Use winrm.cmd to configure TrustedHosts. Note that computers in the TrustedHosts list might not be authenticated. For more information on how to set TrustedHosts run the following command: winrm help config."
  },
  "message": ""
}

Event ID 64: Auto-detecting proxy settings

#
Channel
Operational

Event ID 65: Proxy AutoDetect done.

#
Channel
Operational

Description

Proxy AutoDetect done.Proxy list: {proxyList} Bypass list: {bypassList}.

Message #

Proxy AutoDetect done.Proxy list: {proxyList} Bypass list: {bypassList}

Fields #

NameDescription
proxyList
bypassList

Event ID 66: Setting proxy info Proxy list: {proxyList} Bypass list: {bypassList}.

#
Channel
Operational

Message #

Setting proxy info  Proxy list: {proxyList}  Bypass list: {bypassList}

Fields #

NameDescription
proxyList
bypassList

Event ID 80: Sending the request for operation {operationName} to destination machine and port {url}:{port}.

#
Channel
Operational

Fields #

NameDescription
operationName
url
port

Event ID 81: Processing client request for operation {operationName}.

#
Channel
Operational

Fields #

NameDescription
operationName

Event ID 82: Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>.

#
Channel
Operational

Fields #

NameDescription
operation
resourceURI

Event ID 83: Leaving the plugin for operation {operation}.

#
Channel
Operational

Fields #

NameDescription
operation

Event ID 84: The maximum number of users (users) executing shell operations has been exceeded.

#
Channel
Operational
Task
Requesthandling

Message #

The maximum number of users (%1) executing shell operations has been exceeded.
Retry after sometime or raise the quota for concurrent shell users.

Fields #

NameDescription
users UInt32

Event ID 85: The senderName user is allowed a maximum number of concurrentShells concurrent shells, which has been exceeded.

#
Channel
Operational
Task
Requesthandling

Message #

The %1 user is allowed a maximum number of %2 concurrent shells, which has been exceeded.
Close existing shells or raise the quota for this user.

Fields #

NameDescription
senderName UnicodeString
concurrentShells UInt32

Event ID 86: The WSMan service could not launch a host process to process the given request.

#
Channel
Operational
Level
Error
Task
Requesthandling

Description

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code errorCode.

Message #

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code %1

Fields #

NameDescription
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "a7975c8f-ac13-49f1-87da-5a984a4ab417",
    "event_source_name": "",
    "event_id": 86,
    "version": 0,
    "level": 2,
    "task": 9,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2026-06-09T04:23:46.6764565+00:00",
    "event_record_id": 7656,
    "correlation": {
      "ActivityID": "6f2e837d-f77f-0005-5e9b-2e6f7ff7dc01",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 5016,
      "thread_id": 12768
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "errorCode": "5"
  },
  "message": "The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code 5"
}

Event ID 87: The WSMan host process was unexpectedly terminated.

#
Channel
Operational
Level
Error
Task
Requesthandling

Description

The WSMan host process was unexpectedly terminated. Error code errorCode.

Message #

The WSMan host process was unexpectedly terminated. Error code %1

Fields #

NameDescription
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 87,
    "version": 0,
    "level": 2,
    "task": 9,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2022-04-07T08:14:06.985298+00:00",
    "event_record_id": 62,
    "correlation": {
      "ActivityID": "DD7B0B6A-4A9E-0000-F00E-7BDD9E4AD801"
    },
    "execution": {
      "process_id": 2576,
      "thread_id": 4764
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "errorCode": 1726
  },
  "message": ""
}

References #

Event ID 90: RunAs was disabled by Group Policy; WSMan service has erased all RunAs credentials.

#
Channel
Operational
Task
Requesthandling

Event ID 91: Creating WSMan shell on server with ResourceUri: resourceUri.

#
Channel
Operational
Level
Informational
Task
Requesthandling

Message #

Creating WSMan shell on server with ResourceUri: %1

Fields #

NameDescription
resourceUri UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 91,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2026-06-13T14:08:50.8998983+00:00",
    "event_record_id": 2400,
    "correlation": {
      "ActivityID": "{C6821FB2-EF88-0004-CD20-82C688EFDC01}"
    },
    "execution": {
      "process_id": 1152,
      "thread_id": 8080
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "resourceUri": "http://schemas.microsoft.com/powershell/Microsoft.PowerShell"
  },
  "message": "Creating WSMan shell on server with ResourceUri: http://schemas.microsoft.com/powershell/Microsoft.PowerShell"
}

References #

Event ID 129: Received the response from Network layer; status: {status}.

#
Channel
Operational

Fields #

NameDescription
statusNTSTATUS reference

Event ID 130: Received the response from Network layer; status: {status}.

#
Channel
Operational

Fields #

NameDescription
statusNTSTATUS reference

Event ID 131: Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: location.

#
Channel
Operational
Task
Responsehandling

Message #

Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: %1

Fields #

NameDescription
location UnicodeString

Event ID 132: WSMan operation operationName completed successfully.

#
Channel
Operational
Level
Informational
Task
Responsehandling
Opcode
Stop

Message #

WSMan operation %1 completed successfully

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 132,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2026-05-29T11:33:36.3971896+00:00",
    "event_record_id": 2389,
    "correlation": {
      "ActivityID": "{1C0E3E7D-EF0B-0006-A053-0E1C0BEFDC01}"
    },
    "execution": {
      "process_id": 1876,
      "thread_id": 1444
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
    }
  },
  "event_data": {
    "operationName": "Put"
  },
  "message": "WSMan operation Put completed successfully"
}

Event ID 133: Sending response error packet for ActionURI: {actionUri}.

#
Channel
Operational

Fields #

NameDescription
actionUri

Event ID 134: Sending response for operation {operationName}.

#
Channel
Operational

Fields #

NameDescription
operationName

Event ID 135: Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT, using next proxy

#
Channel
Operational
Task
Responsehandling

Event ID 136: Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED, using next proxy

#
Channel
Operational
Task
Responsehandling

Event ID 137: Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved.

#
Channel
Operational
Task
Responsehandling

Description

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation.

Message #

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation

Event ID 138: The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)

#
Channel
Operational
Level
Error
Task
Responsehandling

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 138,
    "version": 0,
    "level": 2,
    "task": 10,
    "opcode": 0,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T16:58:52.389986+00:00",
    "event_record_id": 1804,
    "correlation": {
      "ActivityID": "028C3802-AD9E-0009-DEA5-8C029EADDC01"
    },
    "execution": {
      "process_id": 1528,
      "thread_id": 10360
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 139: The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE)

#
Channel
Operational
Task
Responsehandling

Event ID 140: Sending HTTP error back to the client due to a transport failure.

#
Channel
Operational

Description

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}.

Message #

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}

Fields #

NameDescription
httpStatus
errorCode

Event ID 141: Sending timeout response for operation: {operationName}.

#
Channel
Operational

Fields #

NameDescription
operationName

Event ID 142: WSMan operation operationName failed, error code errorCode.

#
Channel
Operational
Level
Error
Task
Responsehandling
Opcode
Stop

Message #

WSMan operation %1 failed, error code %2

Fields #

NameDescription
operationName UnicodeString
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 142,
    "version": 0,
    "level": 2,
    "task": 10,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2023-11-06T00:47:48.782597+00:00",
    "event_record_id": 84,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-9DAB-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 16312
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "operationName": "Enumeration",
    "errorCode": 2150858770
  },
  "message": ""
}

References #

Event ID 143: Received the response from Network layer; status: 200 (HTTP_STATUS_OK)

#
Channel
Operational

Event ID 145: WSMan operation operationName started with resourceUri resourceUri.

#
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Message #

WSMan operation %1 started with resourceUri %2

Fields #

NameDescription
operationName UnicodeString
resourceUri UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 145,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2026-05-29T11:33:36.3112691+00:00",
    "event_record_id": 2388,
    "correlation": {
      "ActivityID": "{1C0E3E7D-EF0B-0006-A053-0E1C0BEFDC01}"
    },
    "execution": {
      "process_id": 1876,
      "thread_id": 1664
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
    }
  },
  "event_data": {
    "operationName": "Put",
    "resourceUri": "http://schemas.microsoft.com/wbem/wsman/1/config"
  },
  "message": "WSMan operation Put started with resourceUri http://schemas.microsoft.com/wbem/wsman/1/config"
}

Event ID 160: Authenticating the user using {authentication} mechanism.

#
Channel
Operational

Fields #

NameDescription
authentication

Event ID 161: authFailureMessage.

#
Channel
Operational
Level
Error
Task
Userauthentication

Message #

%1

Fields #

NameDescription
authFailureMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 161,
    "version": 0,
    "level": 2,
    "task": 7,
    "opcode": 0,
    "keywords": 4611686018427387914,
    "time_created": "2023-11-06T00:47:48.782381+00:00",
    "event_record_id": 83,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0002-A38B-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 16312
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "authFailureMessage": "The client cannot connect to the destination specified in the request. Verify that the service on the destination is running and is accepting requests. Consult the logs and documentation for the WS-Management service running on the destination, most commonly IIS or WinRM. If the destination is the WinRM service, run the following command on the destination to analyze and configure the WinRM service: \"winrm quickconfig\"."
  },
  "message": ""
}

References #

Event ID 162: Authenticating the user failed.

#
Channel
Operational
Level
Error
Task
Userauthentication

Description

Authenticating the user failed. The credentials didn't work.

Message #

Authenticating the user failed. The credentials didn't work.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 162,
    "version": 0,
    "level": 2,
    "task": 7,
    "opcode": 0,
    "keywords": 4611686018427387914,
    "time_created": "2026-03-13T17:03:29.975606+00:00",
    "event_record_id": 1873,
    "correlation": {
      "ActivityID": "028C3802-AD9E-0009-E2AC-8C029EADDC01"
    },
    "execution": {
      "process_id": 8184,
      "thread_id": 4952
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 163: The authentication mechanism (authClient) requested by the client is not supported by the server.

#
Channel
Operational
Task
Userauthentication

Message #

The authentication mechanism (%1) requested by the client is not supported by the server.
Possible authentication mechanisms reported by server: %2 %3 %4 %5 %6

Fields #

NameDescription
authClient UnicodeString
authServer1 UnicodeString
authServer2 UnicodeString
authServer3 UnicodeString
authServer4 UnicodeString
authServer5 UnicodeString

Event ID 164: The destination computer (destinationMachine) returned an 'access denied' error.

#
Channel
Operational
Task
Userauthentication

Description

The destination computer (destinationMachine) returned an 'access denied' error. Verify your credentials are correct.

Message #

The destination computer (%1) returned an 'access denied' error. Verify your credentials are correct.

Fields #

NameDescription
destinationMachine UnicodeString

Event ID 165: The authentication mechanism requested by the proxy is not supported by the client.

#
Channel
Operational
Task
Userauthentication

Description

The authentication mechanism requested by the proxy is not supported by the client. The only proxy authentication mechanism supported are Negotiate, Basic or Digest.

Message #

The authentication mechanism requested by the proxy is not supported by the client. The only proxy authentication mechanism supported are Negotiate, Basic or Digest. 
Possible authentication mechanisms reported by proxy: %1 %2 %3 %4 %5

Fields #

NameDescription
authProxy1 UnicodeString
authProxy2 UnicodeString
authProxy3 UnicodeString
authProxy4 UnicodeString
authProxy5 UnicodeString

Event ID 166: The chosen authentication mechanism is {auth}.

#
Channel
Operational

Fields #

NameDescription
auth

Event ID 168: Sending HTTP 401 response to the client and disconnect the connection after sending the response

#
Channel
Operational

Event ID 169

#
Channel
Operational
Level
Informational

Fields #

NameDescription
username
authenticationMechanism

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 169,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 0,
    "keywords": 4611686018427387916,
    "time_created": "2019-05-20T15:54:32.564901+00:00",
    "event_record_id": 861,
    "correlation": {
      "ActivityID": "8534C364-2CC0-0001-C84D-A5F46C0FD501"
    },
    "execution": {
      "process_id": 1204,
      "thread_id": 3068
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "IEWIN7",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "username": "iewin7\\ieuser",
    "authenticationMechanism": "NTLM"
  },
  "message": ""
}

References #

Event ID 170: The authentication using client certificate with subject {subject} done successfully.

#
Channel
Operational

Fields #

NameDescription
subject

Event ID 171: Authenticating the user with the proxy failed.

#
Channel
Operational
Task
Userauthentication

Description

Authenticating the user with the proxy failed. The credentials didn't work.

Message #

Authenticating the user with the proxy failed. The credentials didn't work.

Event ID 172: The server certificate on the destination computer (machineName:port) has the following errors: error1 error2 error3 error4 error5 error6 error7 error8.

#
Channel
Operational
Task
Userauthentication

Description

The server certificate on the destination computer (machineName:port) has the following errors: error1 error2 error3 error4 error5 error6 error7 error8. Fix the server certificate and try again.

Message #

The server certificate on the destination computer (%1:%2) has the following errors: %3 %4 %5 %6 %7 %8 %9 %10. Fix the server certificate and try again.

Fields #

NameDescription
machineName UnicodeString
port UnicodeString
error1 UnicodeString
error2 UnicodeString
error3 UnicodeString
error4 UnicodeString
error5 UnicodeString
error6 UnicodeString
error7 UnicodeString
error8 UnicodeString

Event ID 173: The WinRM service has terminated param1 unauthenticated connections over the past param2 minutes to maintain healthy system state.

#
Channel
Operational
Task
Userauthentication

Description

The WinRM service has terminated param1 unauthenticated connections over the past param2 minutes to maintain healthy system state. This will likely happen if the service is overloaded or if the service is under an authentication based attack. Action: Enable and observe Windows Remote Management Analytic log and look for warning events with Id 1843. These include additional information about the clients that got abruptly terminated.

Message #

The WinRM service has terminated %1 unauthenticated connections over the past %2 minutes to maintain healthy system state. This will likely happen if the service is overloaded or if the service is under an authentication based attack. 

 Action: 
Enable and observe Windows Remote Management Analytic log and look for warning events with Id 1843. These include additional information about the clients that got abruptly terminated.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 192: The authorization of the user failed with error errorCode.

#
Channel
Operational
Level
Informational
Task
Userauthorization

Message #

The authorization of the user failed with error %1

Fields #

NameDescription
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 192,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 0,
    "keywords": 4611686018427387916,
    "time_created": "2026-03-13T17:30:10.610317+00:00",
    "event_record_id": 2649,
    "correlation": {
      "ActivityID": "DF92C490-B30B-0005-A2C8-92DF0BB3DC01"
    },
    "execution": {
      "process_id": 6952,
      "thread_id": 2464
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "errorCode": 5
  },
  "message": ""
}

Event ID 193: Request for user param1 (param2) will be executed using WinRM virtual account param3 (param4).

#
Channel
Operational
Level
Informational
Task
Userauthorization

Message #

Request for user %1 (%2) will be executed using WinRM virtual account %3 (%4)

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 193,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 0,
    "keywords": 4611686018427387916,
    "time_created": "2019-05-20T15:54:32.564901+00:00",
    "event_record_id": 863,
    "correlation": {
      "ActivityID": "8534C364-2CC0-0001-C84D-A5F46C0FD501"
    },
    "execution": {
      "process_id": 1204,
      "thread_id": 3068
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "IEWIN7",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 194: The authorization of the user failed with error {errorCode}.

#
Channel
Operational

Fields #

NameDescription
errorCode

Event ID 208: The Winrm service is starting

#
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 208,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 1,
    "keywords": 4611686018427387908,
    "time_created": "2026-05-29T16:33:03.9687823+00:00",
    "event_record_id": 2391,
    "correlation": {},
    "execution": {
      "process_id": 3584,
      "thread_id": 3776
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The Winrm service is starting"
}

Event ID 209: The Winrm service started successfully

#
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 209,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2026-05-29T16:33:06.8327959+00:00",
    "event_record_id": 2392,
    "correlation": {
      "ActivityID": "{C6821FB2-EF88-0004-CD20-82C688EFDC01}"
    },
    "execution": {
      "process_id": 3584,
      "thread_id": 3776
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The Winrm service started successfully"
}

Event ID 210: The WinRM service is unable to start because of a failure during initialization.

#
Channel
Operational
Task
Winrmservicestart/stop
Opcode
Stop

Description

The WinRM service is unable to start because of a failure during initialization. The error code is errorCode.

Message #

The WinRM service is unable to start because of a failure during initialization. The error code is %1

Fields #

NameDescription
errorCode UInt32

Event ID 211: The Winrm service is stopping

#
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 211,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2026-06-13T05:22:34.5173466+00:00",
    "event_record_id": 1741,
    "correlation": {
      "ActivityID": "{55D4FF8A-EF8A-0002-1E00-D5558AEFDC01}"
    },
    "execution": {
      "process_id": 3676,
      "thread_id": 924
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The Winrm service is stopping"
}

Event ID 212: The Winrm service was stopped successfully

#
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop
Opcode
Stop

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 212,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 2,
    "keywords": 4611686018427387908,
    "time_created": "2026-06-13T05:22:34.5438732+00:00",
    "event_record_id": 1742,
    "correlation": {
      "ActivityID": "{55D4FF8A-EF8A-0002-1E00-D5558AEFDC01}"
    },
    "execution": {
      "process_id": 3676,
      "thread_id": 924
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The Winrm service was stopped successfully"
}

Event ID 213: The WSMan service could not load current configuration settings as the settings are corrupted.

#
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service could not load current configuration settings as the settings are corrupted. The service is started with default settings instead.

Message #

The WSMan service could not load current configuration settings as the settings are corrupted. The service is started with default settings instead. 

 User Action 
 Use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{}

Event ID 214: The WSMan client could not load current configuration settings as the settings are corrupted.

#
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan client could not load current configuration settings as the settings are corrupted. The client is operating with default settings instead.

Message #

The WSMan client could not load current configuration settings as the settings are corrupted. The client is operating with default settings instead. 

 User Action 
 Start the WinRM service and use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{}

Event ID 215: The WSMan service failed to read configuration of the following plugin.

#
Channel
Operational
Task
Winrmservicestart/stop

Message #

The WSMan service failed to read configuration of the following plugin: 
 %1. 

The error received was %2: %%%2 
 %3.

 User Action 
 Make sure this plugin configuration is valid.

Fields #

NameDescription
pluginName UnicodeString
errorcode UnicodeString
errordetail UnicodeString

Event ID 216: The WSMan service failed to restart the plugins marked for AutoRestart.

#
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service failed to restart the plugins marked for AutoRestart. The error code received was errorcode.

Message #

The WSMan service failed to restart the plugins marked for AutoRestart. The error code received was %1.

Fields #

NameDescription
errorcode UnicodeString

Event ID 217: The WSMan service failed to restart the pluginName plugin on service startup.

#
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service failed to restart the pluginName plugin on service startup. The error code received was errorcode.

Message #

The WSMan service failed to restart the %1 plugin on service startup. The error code received was %2.

Fields #

NameDescription
pluginName UnicodeString
errorcode UInt32

Event ID 218: The WSMan service successfully restarted the following plugin on service startup: pluginName.

#
Channel
Operational
Task
Winrmservicestart/stop

Message #

The WSMan service successfully restarted the following plugin on service startup: %1.

Fields #

NameDescription
pluginName UnicodeString

Event ID 219: The WSMan shell instance param1 will no longer support disconnect reconnect functionality because a non-supported request was sent by the client.

#
Channel
Operational
Task
Winrmservicestart/stop

Message #

The WSMan shell instance %1 will no longer support disconnect reconnect functionality because a non-supported request was sent by the client.

Fields #

NameDescription
param1 UnicodeString

Event ID 224: message.

#
Channel
Operational
Level
Informational
Task
Winrmconfiguration

Message #

%1

Fields #

NameDescription
message UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 224,
    "version": 0,
    "level": 4,
    "task": 12,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2026-03-13T17:01:46.087745+00:00",
    "event_record_id": 873,
    "correlation": {
      "ActivityID": "A84E255E-A05B-0007-9C29-4EA85BA0DC01"
    },
    "execution": {
      "process_id": 1732,
      "thread_id": 9060
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "message": "Enable the WinRM firewall exception. "
  },
  "message": ""
}

Event ID 229: The WinRM param1 failed to register for group policy change notifications.

#
Channel
Operational
Task
Winrmconfiguration

Description

The WinRM param1 failed to register for group policy change notifications. The error code is param2.

Message #

The WinRM %1 failed to register for group policy change notifications. The error code is %2.

Fields #

NameDescription
param1 UnicodeString
param2 UInt32

Event ID 230: Deletion of registry key param1 resulted in access denied.

#
Channel
Operational
Task
Winrmconfiguration

Description

Deletion of registry key param1 resulted in access denied. If this registry entry is not marked specifically as read only, this seems like a potential issue.

Message #

Deletion of registry key %1 resulted in access denied. If this registry entry is not marked specifically as read only, this seems like a potential issue.

Fields #

NameDescription
param1 UnicodeString

Event ID 254: Activity Transfer

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 254,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387942,
    "time_created": "2023-11-06T00:47:48.782378+00:00",
    "event_record_id": 82,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0002-A38B-E4E43710DA01",
      "RelatedActivityID": "E4DB489E-1037-0000-9DAB-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 16312
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 255: Activity Transfer

#
Channel
Analytic
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 255,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x2000000000000026",
    "time_created": "2026-06-02T05:32:28.985+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0007-045C-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 257: Initializing WSMan API

#
Channel
Analytic

Event ID 258: Initialization of WSMan API failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 259: Deinitializing WSMan API

#
Channel
Analytic

Event ID 260: Deinitialization of WSMan API failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 261: Creating WSMan Session.

#
Channel
Analytic

Description

Creating WSMan Session. The connection string is: {connection}.

Message #

Creating WSMan Session. The connection string is: {connection}

Fields #

NameDescription
connection

Event ID 262: WSMan Create Session operation failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 263: Closing WSMan Session

#
Channel
Analytic

Event ID 264: Closing WSMan Session failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 265: Setting WSMan Session Option ({optionCode}) with value ({optionValue}) completed successfuly.

#
Channel
Analytic

Fields #

NameDescription
optionCode
optionValue

Event ID 266: Creating WSMan shell with the ResourceUri: {resourceUri}.

#
Channel
Analytic

Fields #

NameDescription
resourceUri

Event ID 267: WSMan shell creation failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 268: Running WSMan command

#
Channel
Analytic

Event ID 269: Running WSMan command failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 270: Closing WSMan command

#
Channel
Analytic

Event ID 271: Closing WSMan shell

#
Channel
Analytic

Event ID 272: Signaling WSMan shell

#
Channel
Analytic

Event ID 273: Signaling WSMan shell; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 274: Closing WSMan operation

#
Channel
Analytic

Event ID 275: Sending input to the shell

#
Channel
Analytic

Event ID 276: Sending input operation failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 277: Calling into WSMan to receive output from the shell

#
Channel
Analytic

Event ID 278: WSMan receive operation failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 279: Calling into WSMan to receive output from the command

#
Channel
Analytic

Event ID 280: Getting message for error code {inputErrorCode} completed successfully.

#
Channel
Analytic

Description

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}.

Message #

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}

Fields #

NameDescription
inputErrorCode
languageCode

Event ID 281: Getting WSMan Session Option ({optionCode}).

#
Channel
Analytic

Fields #

NameDescription
optionCode

Event ID 282: Access Denied error: the {apiCall} API caller does not match the creator of the application object.

#
Channel
Analytic

Fields #

NameDescription
apiCall

Event ID 283: Plug-in reporting context for operation operationName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
WSManAPIcall

Message #

Plug-in reporting context for operation %1

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 283,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.993+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E6F0EC88-0EBD-4322-8998-6DA0441305E6}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "Command"
  },
  "message": "Task.ApiCall"
}

Event ID 284: Plug-in reporting data object for operation operationName.

#
Channel
Analytic
Task
WSManAPIcall

Message #

Plug-in reporting data object for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 285: Plug-in reporting data object and EPR for operation operationName.

#
Channel
Analytic
Task
WSManAPIcall

Message #

Plug-in reporting data object and EPR for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 286: Plug-in reporting data object and bookmark for operation operationName.

#
Channel
Analytic
Task
WSManAPIcall

Message #

Plug-in reporting data object and bookmark for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 287: Plug-in reporting data for operation Receive

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 287,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.985+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0008-7B94-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Task.ApiCall"
}

Event ID 288: Plug-in reporting operation complete for operationName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
WSManAPIcall

Message #

Plug-in reporting operation complete for %1

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 288,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.986+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0007-005C-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "Receive"
  },
  "message": "Task.ApiCall"
}

Event ID 289: Plug-in getting operational information for parameter parameters and operation operationName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
WSManAPIcall

Message #

Plug-in getting operational information for parameter %1 and operation %2

Fields #

NameDescription
parameters UInt32
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 289,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.993+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E6F0EC88-0EBD-4322-8998-6DA0441305E6}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "Command",
    "parameters": 5
  },
  "message": "Task.ApiCall"
}

Event ID 290: Plug-in reporting the authorization for user username completed with error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall

Message #

Plug-in reporting the authorization for user %1 completed with error code %2

Fields #

NameDescription
username UnicodeString
errorCode UInt32

Event ID 291: Plug-in reporting the authorization operation completed with error errorCode for operation operation and ResourceUri resourceUri.

#
Channel
Analytic
Task
WSManAPIcall

Message #

Plug-in reporting the authorization operation completed with error %1 for operation %2 and ResourceUri %3

Fields #

NameDescription
errorCode UInt32
operation UnicodeString
resourceUri UnicodeString

Event ID 292: Updating the quota for the user username with error code errorCode.

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall

Message #

Updating the quota for the user %1 with error code %2
 maxAllowedConcurrentShells=%3
 maxAllowedConcurrentOperations=%4
 timeslotSize=%5
 maxAllowedOperationsPerTimeslot=%6

Fields #

NameDescription
username UnicodeString
errorCode UInt32
maxAllowedConcurrentShells UInt32
maxAllowedConcurrentOperations UInt32
timeslotSize UInt32
maxAllowedOperationsPerTimeslot UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 292,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": 2305843009213693956,
    "time_created": "2026-07-19T03:23:52.775501300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{9882e99c-15c8-4439-9416-a4bddf9adaa8}"
    },
    "execution": {
      "process_id": 12348,
      "thread_id": 12532
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "errorCode": "0",
    "maxAllowedConcurrentOperations": "2147483647",
    "maxAllowedConcurrentShells": "2147483647",
    "maxAllowedOperationsPerTimeslot": "0",
    "timeslotSize": "0",
    "username": "REDACTED\\grounding-user"
  },
  "message": "Updating the quota for the user REDACTED\\grounding-user with error code 0\n maxAllowedConcurrentShells=2147483647\n maxAllowedConcurrentOperations=2147483647\n timeslotSize=0\n maxAllowedOperationsPerTimeslot=0 "
}

Event ID 293: Initialization of WSMan API completed successfuly

#
Channel
Analytic

Event ID 294: Deinitialization of WSMan API completed successfuly

#
Channel
Analytic

Event ID 295: WSMan Create Session operation completed successfuly

#
Channel
Analytic

Event ID 296: Setting WSMan Session Option ({optionCode}) failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
optionCode
errorCode

Event ID 297: Closing WSMan Session completed successfuly

#
Channel
Analytic

Event ID 298: Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
inputErrorCode
errorCode

Event ID 299: Signaling WSMan command failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 300: Signaling WSMan command

#
Channel
Analytic

Event ID 301: Closing WSMan shell failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 302: Closing WSMan command failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 303: Closing WSMan {operationName} operation completed successfully.

#
Channel
Analytic

Fields #

NameDescription
operationName

Event ID 304: Closing WSMan {operationName} operation failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
operationName
errorCode

Event ID 305: Sending input to the command

#
Channel
Analytic

Event ID 306: The WinRM service loaded the following plugin: provider (path).

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Start

Message #

The WinRM service loaded the following plugin: %1 (%2)

Fields #

NameDescription
provider UnicodeString
path UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 306,
    "version": 1,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 2305843009213693956,
    "time_created": "2026-07-19T03:23:52.785418400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{9882e99c-15c8-4439-9416-a4bddf9adaa8}"
    },
    "execution": {
      "process_id": 12348,
      "thread_id": 12532
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "path": "C:\\Windows\\system32\\pwrshplugin.dll",
    "provider": "microsoft.powershell"
  },
  "message": "The WinRM service loaded the following plugin: microsoft.powershell (C:\\Windows\\system32\\pwrshplugin.dll) "
}

Event ID 307: The WinRM service unloaded the following plugin: provider (path).

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Stop

Message #

The WinRM service unloaded the following plugin: %1 (%2)

Fields #

NameDescription
provider UnicodeString
path UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 307,
    "version": 1,
    "level": 4,
    "task": 5,
    "opcode": 2,
    "keywords": 2305843009213693956,
    "time_created": "2026-07-19T03:23:52.687991200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{bf440000-0bf1-0001-217c-53bff10bdd01}"
    },
    "execution": {
      "process_id": 12308,
      "thread_id": 10792
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "path": "C:\\Windows\\system32\\pwrshplugin.dll",
    "provider": "microsoft.windows.servermanagerworkflows"
  },
  "message": "The WinRM service unloaded the following plugin: microsoft.windows.servermanagerworkflows (C:\\Windows\\system32\\pwrshplugin.dll) "
}

Event ID 308: The plugin called WSManPluginGetConfiguration with the parameter Flags and obtained a return value of Result.

#
Channel
Analytic
Task
WSManAPIcall

Message #

The plugin called WSManPluginGetConfiguration with the parameter %1 and obtained a return value of %2.

Fields #

NameDescription
Flags UInt32
Result UInt32

Event ID 309: The plugin called WSManPluginReportCompletion with the parameter Flags and obtained a return value of Result.

#
Channel
Analytic
Task
WSManAPIcall

Message #

The plugin called WSManPluginReportCompletion with the parameter %1 and obtained a return value of %2.

Fields #

NameDescription
Flags UInt32
Result UInt32

Event ID 310: The plugin Plugin is being shut down because it was idle for longer than the configured HostIdleTimeoutSecs quota.

#
Channel
Analytic
Task
WSManAPIcall

Message #

The plugin %1 is being shut down because it was idle for longer than the configured HostIdleTimeoutSecs quota.

Fields #

NameDescription
Plugin UnicodeString

Event ID 311: Signaling WSMan command failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Signaling WSMan command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 312: Signaling WSMan command

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Event ID 313: Sending input to the command

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Event ID 314: Sending input to the shell

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Event ID 315: Sending input operation failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Sending input operation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 316: Calling into WSMan to receive output from the shell

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 316,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:08.099287200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 9432
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Calling into WSMan to receive output from the shell"
}

Event ID 317: WSMan receive operation failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

WSMan receive operation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 318: Calling into WSMan to receive output from the command

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 318,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:08.280188100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 14300
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Calling into WSMan to receive output from the command"
}

Event ID 319: Getting message for error code inputErrorCode completed successfully.

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Stop

Description

Getting message for error code inputErrorCode completed successfully. The languageCode parameter was: languageCode.

Message #

Getting message for error code %1 completed successfully. The languageCode parameter was: %2

Fields #

NameDescription
inputErrorCode UInt32
languageCode UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 319,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 11300,
      "thread_id": 4040
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-WinRM",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:37:05.792Z",
    "version": 0
  },
  "event_data": {
    "inputErrorCode": 5,
    "languageCode": "en-US"
  },
  "message": ""
}

Event ID 320: Getting WSMan Session Option (optionCode) - optionName.

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Start

Message #

Getting WSMan Session Option (%1) - %2.

Fields #

NameDescription
optionCode UInt32
optionName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 320,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:07.738134900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 14120
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "optionCode": "29",
    "optionName": "INVALID_SESSION_OPTION"
  },
  "message": "Getting WSMan Session Option (29) - INVALID_SESSION_OPTION."
}

Event ID 321: Signaling WSMan shell

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Event ID 322: Signaling WSMan shell, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Signaling WSMan shell, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 323: Closing WSMan operation

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 323,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:08.551521800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 11048
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Closing WSMan operation"
}

Event ID 324: Closing WSMan operationName operation completed successfully.

#
Channel
Analytic
Level
Informational
Task
WSManAPIcall
Opcode
Stop

Message #

Closing WSMan %1 operation completed successfully

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 324,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 2,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:08.551582300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 11048
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "ReceiveShellOutput"
  },
  "message": "Closing WSMan ReceiveShellOutput operation completed successfully"
}

Event ID 325: Disconnecting shell with Id : argument.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Message #

Disconnecting shell with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 326: Disconnecting shell failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Disconnecting shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 327: Reconnecting shell with Id : argument.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Message #

Reconnecting shell  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 328: Reconnecting shell failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Reconnecting shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 329: Connecting shell with Id : argument.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Message #

Connecting shell  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 330: Connecting shell failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Connecting shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 331: Reconnecting shell command with Id : argument.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Message #

Reconnecting shell command  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 332: Reconnecting shell command failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Reconnecting shell command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 333: Connecting shell command with Id : argument.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Message #

Connecting shell command  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 334: Connecting shell command failed, error code errorCode.

#
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Message #

Connecting shell command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 512: Auto-detecting proxy settings

#
Channel
Analytic
Task
Auto_detectingproxysettings
Opcode
Start

Event ID 513: Proxy AutoDetect done.

#
Channel
Analytic
Task
Auto_detectingproxysettings
Opcode
Stop

Message #

Proxy AutoDetect done.
Proxy list: %1 
Bypass list: %2

Fields #

NameDescription
proxyList UnicodeString
bypassList UnicodeString

Event ID 514: Setting proxy info.

#
Channel
Analytic
Task
Auto_detectingproxysettings

Message #

Setting proxy info 
 Proxy list: %1 
 Bypass list: %2

Fields #

NameDescription
proxyList UnicodeString
bypassList UnicodeString

Event ID 768: Processing client request for operation {operationName}.

#
Channel
Analytic

Fields #

NameDescription
operationName

Event ID 769: Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>.

#
Channel
Analytic

Fields #

NameDescription
operation
resourceURI

Event ID 770: Leaving the plugin for operation {operation}.

#
Channel
Analytic

Fields #

NameDescription
operation

Event ID 771: SOAP [client sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

#
Channel
Analytic
Task
Requesthandling

Message #

SOAP [client sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Event ID 772: SOAP [listener receiving index index of totalChunks total chunks (bytes bytes)] SoapDocument.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
Requesthandling

Message #

SOAP [listener receiving index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 772,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": "0x2000000000000005",
    "time_created": "2026-06-02T05:32:28.992+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0009-EB78-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 4672,
      "thread_id": 17880
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "SoapDocument": "<s:Envelope xmlns:rsp=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell\" xmlns:s=\"http://www.w3.org/2003/05/soap-envelope\" xmlns:wsa=\"http://schemas.xmlsoap.org/ws/2004/08/addressing\" xmlns:wsman=\"http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\" xmlns:wsmv=\"http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd\"><s:Header><wsa:Action s:mustUnderstand=\"true\">http://schemas.microsoft.com/wbem/wsman/1/windows/shell/Command</wsa:Action><wsmv:DataLocale s:mustUnderstand=\"false\" xml:lang=\"en-US\" /><wsman:Locale s:mustUnderstand=\"false\" xml:lang=\"en-US\" /><wsman:MaxEnvelopeSize s:mustUnderstand=\"true\">512000</wsman:MaxEnvelopeSize><wsa:MessageID>uuid:FC55EFC6-1167-4F07-AE78-171E27FA4F28</wsa:MessageID><wsman:OperationTimeout>PT50S</wsman:OperationTimeout><wsa:ReplyTo><wsa:Address s:mustUnderstand=\"true\">http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</wsa:Address></wsa:ReplyTo><wsman:ResourceURI s:mustUnderstand=\"true\">http://schemas.microsoft.com/powershell/Microsoft.PowerShell</wsman:ResourceURI><wsmv:SessionId s:mustUnderstand=\"false\">uuid:BA24F3F0-F769-42AA-B48B-1C82E340AD0D</wsmv:SessionId><wsa:To>http://10.2.10.11:5985/wsman</wsa:To><wsman:OptionSet s:mustUnderstand=\"true\"><wsman:Option Name=\"WINRS_SKIP_CMD_SHELL\">False</wsman:Option></wsman:OptionSet><wsman:SelectorSet><wsman:Selector Name=\"ShellId\">3F291011-56F8-4FA3-A480-3E3164B15333</wsman:Selector></wsman:SelectorSet></s:Header><s:Body><rsp:CommandLine CommandId=\"7F4BC879-EF34-415C-A317-A9D1E7110033\"><r",
    "bytes": 3000,
    "index": 1,
    "totalChunks": 4
  },
  "message": "Task.RequestHandling"
}

Event ID 773: The {senderName} user is allowed a maximum number of {concurrentShells} concurrent shells; which has been exceeded.

#
Channel
Analytic

Description

The {senderName} user is allowed a maximum number of {concurrentShells} concurrent shells; which has been exceeded.Close existing shells or raise the quota for this user.

Message #

The {senderName} user is allowed a maximum number of {concurrentShells} concurrent shells; which has been exceeded.Close existing shells or raise the quota for this user.

Fields #

NameDescription
senderName
concurrentShells

Event ID 774: The senderName user is allowed a maximum number of concurrentOperations concurrent operations, which has been exceeded.

#
Channel
Analytic
Task
Requesthandling

Message #

The %1 user is allowed a maximum number of %2 concurrent operations, which has been exceeded.
Close existing operations for this user, or raise the quota for this user.

Fields #

NameDescription
senderName UnicodeString
concurrentOperations UInt32

Event ID 775: The user load quota of requests requests per windowTime seconds has been exceeded.

#
Channel
Analytic
Task
Requesthandling

Message #

The user load quota of %1 requests per %2 seconds has been exceeded.
Send future requests at a slower rate or raise the quota for the %3 user.
The next request from this user will not be approved for at least %4 milliseconds.

Fields #

NameDescription
requests UInt32
windowTime UInt32
senderName UnicodeString
delayHint UInt32

Event ID 776: The system load quota of requests requests per windowTime seconds has been exceeded.

#
Channel
Analytic
Task
Requesthandling

Message #

The system load quota of %1 requests per %2 seconds has been exceeded.
Send future requests at a slower rate or raise the system quota.
The next request from the user %3 will not be approved for at least %4 milliseconds.

Fields #

NameDescription
requests UInt32
windowTime UInt32
senderName UnicodeString
delayHint UInt32

Event ID 777: The maximum number of users ({users}) executing shell operations has been exceeded.

#
Channel
Analytic

Description

The maximum number of users ({users}) executing shell operations has been exceeded.Retry after sometime or raise the quota for concurrent shell users.

Message #

The maximum number of users ({users}) executing shell operations has been exceeded.Retry after sometime or raise the quota for concurrent shell users.

Fields #

NameDescription
users

Event ID 778: Sending the request for operation {operationName} to destination machine and port {url}:{port}.

#
Channel
Analytic

Fields #

NameDescription
operationName
url
port

Event ID 779: SOAP [client sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

#
Channel
Analytic
Level
Informational
Task
Requesthandling

Message #

SOAP [client sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 779,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": "0x2000000000000003",
    "time_created": "2026-07-19T03:40:07.742122900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 14120
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "index": "1",
    "totalChunks": "4",
    "bytes": "1500",
    "SoapDocument": "<s:Envelope xmlns:s=\"http://www.w3.org/2003/05/soap-envelope\" xmlns:a=\"http://schemas.xmlsoap.org/ws/2004/08/addressing\" xmlns:w=\"http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\" xmlns:p=\"http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd\"><s:Header><a:To>http://localhost:5985/wsman?PSVersion=5.1.22621.6060</a:To><w:ResourceURI s:mustUnderstand=\"true\">http://schemas.microsoft.com/powershell/Microsoft.PowerShell</w:ResourceURI><a:ReplyTo><a:Address s:mustUnderstand=\"true\">http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:Address></a:ReplyTo><a:Action s:mustUnderstand=\"true\">http://schemas.xmlsoap.org/ws/2004/09/transfer/Create</a:Action><w:MaxEnvelopeSize s:mustUnderstand=\"true\">512000</w:MaxEnvelopeSize><a:MessageID>uuid:C3C52D62-DE8B-45EA-BCEA-E16D8E04D840</a:MessageID><w:Locale xml:lang=\"en-US\" s:mustUnderstand=\"false\" /><p:DataLocale xml:lang=\"en-US\" s:mustUnderstand=\"false\" /><p:ActivityId s:mustUnderstand=\"false\">BF440000-0BF1-0007-401C-4DBFF10BDD01</p:ActivityId><p:SessionId s:mustUnderstand=\"false\">uuid:EEEB8940-22E1-4D3D-BC6A-16ECE01C45F5</p:SessionId><p:OperationID s:mustUnderstand=\"false\">uuid:594C6A9C-2DEE-4C06-AE57-27403E56CD8C</p:OperationID><p:SequenceId s:mustUnderstand=\"false\">1</p:SequenceId><w:OptionSet xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" s:mustUnderstand=\"true\"><w:Option Name=\"protocolversion\" MustComply=\"true\">2.3</w:Option></w:OptionSet><w:OperationTimeout>PT180.000S</w:OperationTimeout><rsp:CompressionType s:mustUnderst"
  },
  "message": "SOAP [client sending index 1 of 4 total chunks (1500 bytes)] <s:Envelope xmlns:s=\"http://www.w3.org/2003/05/soap-envelope\" xmlns:a=\"http://schemas.xmlsoap.org/ws/2004/08/addressing\" xmlns:w=\"http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\" xmlns:p=\"http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd\"><s:Header><a:To>http://localhost:5985/wsman?PSVersion=5.1.22621.6060</a:To><w:ResourceURI s:mustUnderstand=\"true\">http://schemas.microsoft.com/powershell/Microsoft.PowerShell</w:ResourceURI><a:ReplyTo><a:Address s:mustUnderstand=\"true\">http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:Address></a:ReplyTo><a:Action s:mustUnderstand=\"true\">http://schemas.xmlsoap.org/ws/2004/09/transfer/Create</a:Action><w:MaxEnvelopeSize s:mustUnderstand=\"true\">512000</w:MaxEnvelopeSize><a:MessageID>uuid:C3C52D62-DE8B-45EA-BCEA-E16D8E04D840</a:MessageID><w:Locale xml:lang=\"en-US\" s:mustUnderstand=\"false\" /><p:DataLocale xml:lang=\"en-US\" s:mustUnderstand=\"false\" /><p:ActivityId s:mustUnderstand=\"false\">BF440000-0BF1-0007-401C-4DBFF10BDD01</p:ActivityId><p:SessionId s:mustUnderstand=\"false\">uuid:EEEB8940-22E1-4D3D-BC6A-16ECE01C45F5</p:SessionId><p:OperationID s:mustUnderstand=\"false\">uuid:594C6A9C-2DEE-4C06-AE57-27403E56CD8C</p:OperationID><p:SequenceId s:mustUnderstand=\"false\">1</p:SequenceId><w:OptionSet xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" s:mustUnderstand=\"true\"><w:Option Name=\"protocolversion\" MustComply=\"true\">2.3</w:Option></w:OptionSet><w:OperationTimeout>PT180.000S</w:OperationTimeout><rsp:CompressionType s:mustUnderst"
}

Event ID 780: The WinRM param1 has encountered network connectivity issues.

#
Channel
Analytic
Task
Requesthandling

Message #

The WinRM %1 has encountered network connectivity issues.

Fields #

NameDescription
param1 UnicodeString

Event ID 781: The WinRM Client is attempting to re-establish a network connection.

#
Channel
Analytic
Task
Requesthandling

Event ID 782: The WinRM Service has detected a new network connection from the client.

#
Channel
Analytic
Task
Requesthandling

Event ID 783: The WinRM param1 has successfully re-established a network connection.

#
Channel
Analytic
Task
Requesthandling

Message #

The WinRM %1 has successfully re-established a network connection.

Fields #

NameDescription
param1 UnicodeString

Event ID 784: The WinRM param1 failed to re-establish a network connection and is reporting a failure.

#
Channel
Analytic
Task
Requesthandling

Message #

The WinRM %1 failed to re-establish a network connection and is reporting a failure.

Fields #

NameDescription
param1 UnicodeString

Event ID 785: The WSMan host process was started for user userName.

#
Channel
Analytic
Level
Informational
Task
Requesthandling

Message #

The WSMan host process was started for user %1.

Fields #

NameDescription
userName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 785,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": 2305843009213693956,
    "time_created": "2026-07-19T03:23:52.772368100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{9c94cb43-b3b2-4240-ad8d-0982f5756559}"
    },
    "execution": {
      "process_id": 7308,
      "thread_id": 6836
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "userName": "REDACTED\\grounding-user"
  },
  "message": "The WSMan host process was started for user REDACTED\\grounding-user. "
}

Event ID 786: The WSMan host process was terminated for user userName.

#
Channel
Analytic
Level
Informational
Task
Requesthandling

Message #

The WSMan host process was terminated for user %1.

Fields #

NameDescription
userName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 786,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": 2305843009213693956,
    "time_created": "2026-07-19T03:23:52.687268400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8c0eabf2-a10d-4419-860c-0a113719a1b9}"
    },
    "execution": {
      "process_id": 7308,
      "thread_id": 8076
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "userName": "REDACTED\\grounding-user"
  },
  "message": "The WSMan host process was terminated for user REDACTED\\grounding-user. "
}

Event ID 787: Sending the request for operation operationName to destination machine and port url:port.

#
Channel
Analytic
Level
Informational
Task
Requesthandling
Opcode
Start

Message #

Sending the request for operation %1 to destination machine and port %2:%3

Fields #

NameDescription
operationName UnicodeString
url UnicodeString
port UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 787,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 1,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:07.756916500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 14120
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "CreateShell",
    "url": "localhost",
    "port": "5985"
  },
  "message": "Sending the request for operation CreateShell to destination machine and port localhost:5985"
}

Event ID 788: Processing client request for operation operationName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
Requesthandling

Message #

Processing client request for operation %1

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 788,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.993+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E6F0EC88-0EBD-4322-8998-6DA0441305E6}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "Command"
  },
  "message": "Task.RequestHandling"
}

Event ID 789: Entering the plugin for operation operation with a ResourceURI of <resourceURI>.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
Requesthandling

Message #

Entering the plugin for operation %1 with a ResourceURI of <%2>

Fields #

NameDescription
operation UnicodeString
resourceURI UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 789,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.993+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E6F0EC88-0EBD-4322-8998-6DA0441305E6}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operation": "Command",
    "resourceURI": "http://schemas.microsoft.com/powershell/Microsoft.PowerShell"
  },
  "message": "Task.RequestHandling"
}

Event ID 790: Leaving the plugin for operation operation.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
Requesthandling
Opcode
Stop

Message #

Leaving the plugin for operation %1

Fields #

NameDescription
operation UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 790,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 2,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.987+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0007-005C-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operation": "Command"
  },
  "message": "Task.RequestHandling"
}

Event ID 791: The WinRM service failed to enumerate DASH/SMASH specifications with MI error: errorCode.

#
Channel
Analytic
Task
Requesthandling

Message #

The WinRM service failed to enumerate DASH/SMASH specifications with MI error: %1.

Fields #

NameDescription
errorCode UInt32

Event ID 1024: Sending response for operation {operationName}.

#
Channel
Analytic

Fields #

NameDescription
operationName

Event ID 1025: Sending response error packet for ActionURI: actionUri.

#
Channel
Analytic
Task
Responsehandling

Message #

Sending response error packet for ActionURI: %1

Fields #

NameDescription
actionUri UnicodeString

Event ID 1026: SOAP [client receiving index index of totalChunks total chunks (bytes bytes)] SoapDocument.

#
Channel
Analytic
Level
Informational
Task
Responsehandling

Message #

SOAP [client receiving index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1026,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 0,
    "keywords": "0x2000000000000003",
    "time_created": "2026-07-19T03:40:08.098699400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 9432
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "index": "1",
    "totalChunks": "2",
    "bytes": "3000",
    "SoapDocument": "<s:Envelope xml:lang=\"en-US\" xmlns:s=\"http://www.w3.org/2003/05/soap-envelope\" xmlns:a=\"http://schemas.xmlsoap.org/ws/2004/08/addressing\" xmlns:x=\"http://schemas.xmlsoap.org/ws/2004/09/transfer\" xmlns:w=\"http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\" xmlns:rsp=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell\" xmlns:p=\"http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd\"><s:Header><a:Action>http://schemas.xmlsoap.org/ws/2004/09/transfer/CreateResponse</a:Action><a:MessageID>uuid:719CA8D8-D21D-4631-A259-26B1828C03DB</a:MessageID><p:OperationID s:mustUnderstand=\"false\">uuid:594C6A9C-2DEE-4C06-AE57-27403E56CD8C</p:OperationID><p:SequenceId>1</p:SequenceId><p:ActivityId>BF440000-0BF1-0006-4864-4CBFF10BDD01</p:ActivityId><a:To>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:To><a:RelatesTo>uuid:C3C52D62-DE8B-45EA-BCEA-E16D8E04D840</a:RelatesTo></s:Header><s:Body><x:ResourceCreated><a:Address>http://localhost:5985/wsman?PSVersion=5.1.22621.6060</a:Address><a:ReferenceParameters><w:ResourceURI>http://schemas.microsoft.com/powershell/Microsoft.PowerShell</w:ResourceURI><w:SelectorSet><w:Selector Name=\"ShellId\">015E90EF-EBFB-4901-A012-606DDDCA47B8</w:Selector></w:SelectorSet></a:ReferenceParameters></x:ResourceCreated><rsp:Shell xmlns:rsp=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell\"><rsp:ShellId>015E90EF-EBFB-4901-A012-606DDDCA47B8</rsp:ShellId><rsp:Name>WinRM1</rsp:Name><rsp:ResourceUri>http://schemas.microsoft.com/powershell/Microsoft.PowerShe"
  },
  "message": "SOAP [client receiving index 1 of 2 total chunks (3000 bytes)] <s:Envelope xml:lang=\"en-US\" xmlns:s=\"http://www.w3.org/2003/05/soap-envelope\" xmlns:a=\"http://schemas.xmlsoap.org/ws/2004/08/addressing\" xmlns:x=\"http://schemas.xmlsoap.org/ws/2004/09/transfer\" xmlns:w=\"http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\" xmlns:rsp=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell\" xmlns:p=\"http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd\"><s:Header><a:Action>http://schemas.xmlsoap.org/ws/2004/09/transfer/CreateResponse</a:Action><a:MessageID>uuid:719CA8D8-D21D-4631-A259-26B1828C03DB</a:MessageID><p:OperationID s:mustUnderstand=\"false\">uuid:594C6A9C-2DEE-4C06-AE57-27403E56CD8C</p:OperationID><p:SequenceId>1</p:SequenceId><p:ActivityId>BF440000-0BF1-0006-4864-4CBFF10BDD01</p:ActivityId><a:To>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:To><a:RelatesTo>uuid:C3C52D62-DE8B-45EA-BCEA-E16D8E04D840</a:RelatesTo></s:Header><s:Body><x:ResourceCreated><a:Address>http://localhost:5985/wsman?PSVersion=5.1.22621.6060</a:Address><a:ReferenceParameters><w:ResourceURI>http://schemas.microsoft.com/powershell/Microsoft.PowerShell</w:ResourceURI><w:SelectorSet><w:Selector Name=\"ShellId\">015E90EF-EBFB-4901-A012-606DDDCA47B8</w:Selector></w:SelectorSet></a:ReferenceParameters></x:ResourceCreated><rsp:Shell xmlns:rsp=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell\"><rsp:ShellId>015E90EF-EBFB-4901-A012-606DDDCA47B8</rsp:ShellId><rsp:Name>WinRM1</rsp:Name><rsp:ResourceUri>http://schemas.microsoft.com/powershell/Microsoft.PowerShe"
}

Event ID 1027: SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

#
Channel
Analytic
Task
Responsehandling

Message #

SOAP [listener sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Event ID 1028: Received the response from Network layer; status: {status}.

#
Channel
Analytic

Fields #

NameDescription
statusNTSTATUS reference

Event ID 1029: Received the response from Network layer; status: {status}.

#
Channel
Analytic

Fields #

NameDescription
statusNTSTATUS reference

Event ID 1030: Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: {location}.

#
Channel
Analytic

Fields #

NameDescription
location

Event ID 1031: WSMan operation {operationName} completed successfully.

#
Channel
Analytic

Fields #

NameDescription
operationName

Event ID 1032: Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT; using next proxy

#
Channel
Analytic

Event ID 1033: Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED; using next proxy

#
Channel
Analytic

Event ID 1034: Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved.

#
Channel
Analytic

Description

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation.

Message #

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation

Event ID 1035: The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)

#
Channel
Analytic

Event ID 1036: The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE)

#
Channel
Analytic

Event ID 1037: The WSMan service could not launch a host process to process the given request.

#
Channel
Analytic

Description

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code {errorCode}.

Message #

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 1038: The WSMan host process was unexpectedly terminated.

#
Channel
Analytic

Description

The WSMan host process was unexpectedly terminated. Error code {errorCode}.

Message #

The WSMan host process was unexpectedly terminated. Error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 1039: Sending HTTP error back to the client due to a transport failure.

#
Channel
Analytic

Description

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}.

Message #

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}

Fields #

NameDescription
httpStatus
errorCode

Event ID 1040: Sending timeout response for operation: {operationName}.

#
Channel
Analytic

Fields #

NameDescription
operationName

Event ID 1041: Enumeration is shutting down

#
Channel
Analytic
Task
Responsehandling

Event ID 1042: WSMan operation {operationName} failed; error code {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
operationName
errorCode

Event ID 1043: Subscription is shutting down

#
Channel
Analytic
Task
Responsehandling

Event ID 1044: SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
Responsehandling

Message #

SOAP [listener sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 1044,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 0,
    "keywords": "0x2000000000000005",
    "time_created": "2026-06-02T05:32:28.986+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0007-005C-818753F0DC01}"
    },
    "execution": {
      "process_id": 5004,
      "thread_id": 22924
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "SoapDocument": "<s:Envelope xml:lang=\"en-US\" xmlns:s=\"http://www.w3.org/2003/05/soap-envelope\" xmlns:a=\"http://schemas.xmlsoap.org/ws/2004/08/addressing\" xmlns:w=\"http://schemas.dmtf.org/wbem/wsman/1/wsman.xsd\" xmlns:rsp=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell\" xmlns:p=\"http://schemas.microsoft.com/wbem/wsman/1/wsman.xsd\"><s:Header><a:Action>http://schemas.microsoft.com/wbem/wsman/1/windows/shell/ReceiveResponse</a:Action><a:MessageID>uuid:90F5637C-A167-41AE-A9AE-EC20D8695A8C</a:MessageID><p:ActivityId>877F78A1-F053-0007-045C-818753F0DC01</p:ActivityId><a:To>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:To><a:RelatesTo>uuid:014D5D3F-4C88-4A51-B929-54F7F851F0AE</a:RelatesTo></s:Header><s:Body><rsp:ReceiveResponse><rsp:Stream Name=\"stdout\" CommandId=\"702889DC-AC6A-4895-9307-B34DF9C1B107\">AAAAAAAAA4AAAAAAAAAAAAMAAABAAQAAAAQQBAARECk/+FajT6SAPjFksVMz3IkocGqslUiTB7NN+cGxB++7vzxTPlBJRD0xNjQ5MiBTWj0wPC9TPg==</rsp:Stream><rsp:Stream Name=\"stdout\" CommandId=\"702889DC-AC6A-4895-9307-B34DF9C1B107\">AAAAAAAAA4EAAAAAAAAAAAMAAABnAQAAAAYQBAARECk/+FajT6SAPjFksVMz3IkocGqslUiTB7NN+cGxB++7vzxPYmogUmVmSWQ9IjAiPjxNUz48STMyIE49IlBpcGVsaW5lU3RhdGUiPjQ8L0kzMj48L01TPjwvT2JqPg==</rsp:Stream><rsp:CommandState CommandId=\"702889DC-AC6A-4895-9307-B34DF9C1B107\" State=\"http://schemas.microsoft.com/wbem/wsman/1/windows/shell/CommandState/Done\"><rsp:ExitCode>0</rsp:ExitCode></rsp:CommandState></rsp:ReceiveResponse></s:Body></s:Envelope>",
    "bytes": 1446,
    "index": 1,
    "totalChunks": 1
  },
  "message": "Task.ResponseHandling"
}

Event ID 1045: Received the response from Network layer; status: 200 (HTTP_STATUS_OK)

#
Channel
Analytic
Level
Informational
Task
Responsehandling
Opcode
Start

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1045,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 1,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:07.915544500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "BF440000-0BF1-0008-F4F4-4ABFF10BDD01"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 11048
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Received the response from Network layer; status: 200 (HTTP_STATUS_OK)"
}

Event ID 1046: An extended semantics callback timed out for the operationName operation.

#
Channel
Analytic
Task
Responsehandling

Message #

An extended semantics callback timed out for the %1 operation.

Fields #

NameDescription
operationName UnicodeString

Event ID 1047: Received the response from Network layer; status: status.

#
Channel
Analytic
Level
Error
Task
Responsehandling
Opcode
Start

Message #

Received the response from Network layer; status: %1

Fields #

NameDescription
status UnicodeStringNTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1047,
    "version": 0,
    "level": 2,
    "task": 10,
    "opcode": 1,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:08.566568700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "BF440000-0BF1-0006-8864-4CBFF10BDD01"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 9432
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "status": "204 (HTTP_STATUS_NO_CONTENT)"
  },
  "message": "Received the response from Network layer; status: 204 (HTTP_STATUS_NO_CONTENT)"
}

Event ID 1048: Sending HTTP error back to the client due to a transport failure.

#
Channel
Analytic
Task
Responsehandling

Message #

Sending HTTP error back to the client due to a transport failure.
The HTTP status code is %1
The error code is %2

Fields #

NameDescription
httpStatus UInt16
errorCode UInt32
extraErrorInfo1 UnicodeString
extraErrorInfo2 UnicodeString

Event ID 1049: Sending timeout response for operation: operationName.

#
Channel
Analytic
Task
Responsehandling

Message #

Sending timeout response for operation: %1

Fields #

NameDescription
operationName UnicodeString

Event ID 1050: Sending response for operation operationName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Informational
Task
Responsehandling

Message #

Sending response for operation %1

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 1050,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 0,
    "keywords": "0x2000000000000004",
    "time_created": "2026-06-02T05:32:28.987+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0009-EB78-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 4672,
      "thread_id": 17880
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "Receive"
  },
  "message": "Task.ResponseHandling"
}

Event ID 1051: Received the response from Network layer; status: status.

#
Channel
Analytic
Task
Responsehandling

Message #

Received the response from Network layer; status: %1

Fields #

NameDescription
status UInt32NTSTATUS reference

Event ID 1052: WSMan operation operationName completed successfully.

#
Channel
Analytic
Level
Informational
Task
Responsehandling
Opcode
Stop

Message #

WSMan operation %1 completed successfully

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1052,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 2,
    "keywords": "0x2000000000000002",
    "time_created": "2026-07-19T03:40:08.099053900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 9432
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "operationName": "CreateShell"
  },
  "message": "WSMan operation CreateShell completed successfully"
}

Event ID 1053: WSMan operation operationName got suspended because of WSMan Shell disconnection.

#
Channel
Analytic
Task
WinrmOperation
Opcode
Stop

Message #

WSMan operation %1 got suspended because of WSMan Shell disconnection.

Fields #

NameDescription
operationName UnicodeString

Event ID 1054: WSMan operation operationName resuming because of WSMan Shell reconnection.

#
Channel
Analytic
Task
WinrmOperation
Opcode
Stop

Message #

WSMan operation %1 resuming because of WSMan Shell reconnection.

Fields #

NameDescription
operationName UnicodeString

Event ID 1280: Sending HTTP 401 response to the client and disconnect the connection after sending the response

#
Channel
Analytic

Event ID 1281: User {username} authenticated successfully using {authenticationMechanism} authentication.

#
Channel
Analytic

Fields #

NameDescription
username
authenticationMechanism

Event ID 1282: The authentication using client certificate with subject {subject} done successfully.

#
Channel
Analytic

Fields #

NameDescription
subject

Event ID 1283: Authenticating the user using {authentication} mechanism.

#
Channel
Analytic

Fields #

NameDescription
authentication

Event ID 1285: Authenticating the user failed.

#
Channel
Analytic

Description

Authenticating the user failed. The credentials didn't work.

Message #

Authenticating the user failed. The credentials didn't work.

Event ID 1286: The authentication mechanism ({authClient}) requested by the client is not supported by the server.

#
Channel
Analytic

Message #

The authentication mechanism ({authClient}) requested by the client is not supported by the server.Possible authentication mechanisms reported by server: {authServer1} {authServer2} {authServer3} {authServer4} {authServer5}

Fields #

NameDescription
authClient
authServer1
authServer2
authServer3
authServer4
authServer5

Event ID 1287: The destination computer ({destinationMachine}) returned an 'access denied' error.

#
Channel
Analytic

Message #

The destination computer ({destinationMachine}) returned an 'access denied' error.Possible authentication mechanisms reported by server: {authServer1} {authServer2} {authServer3} {authServer4} {authServer5}.Verify your credentials are correct.

Fields #

NameDescription
destinationMachine
authServer1
authServer2
authServer3
authServer4
authServer5

Event ID 1288: The authentication mechanism requested by the proxy is not supported by the client.

#
Channel
Analytic

Message #

The authentication mechanism requested by the proxy is not supported by the client. The only proxy authentication mechanism supported are Negotiate; Basic or Digest. Possible authentication mechanisms reported by proxy: {authProxy1} {authProxy2} {authProxy3} {authProxy4} {authProxy5}

Fields #

NameDescription
authProxy1
authProxy2
authProxy3
authProxy4
authProxy5

Event ID 1289: The chosen authentication mechanism is {auth}.

#
Channel
Analytic

Fields #

NameDescription
auth

Event ID 1291: Network layer AutoLogon policy was set to Low as a result of a HTTP 401 response from Network layer

#
Channel
Analytic
Task
Userauthentication

Event ID 1292: Network layer AutoLogon policy was set to High

#
Channel
Analytic
Task
Userauthentication

Event ID 1293: The chosen authentication mechanism is auth.

#
Channel
Analytic
Level
Informational
Task
Userauthentication

Message #

The chosen authentication mechanism is %1

Fields #

NameDescription
auth UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1293,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 0,
    "keywords": "0x200000000000000A",
    "time_created": "2026-07-19T03:40:07.749824100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "015E90EF-EBFB-4901-A012-606DDDCA47B8"
    },
    "execution": {
      "process_id": 12908,
      "thread_id": 14120
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "auth": "Negotiate"
  },
  "message": "The chosen authentication mechanism is Negotiate"
}

Event ID 1294: Sending HTTP 401 response to the client and disconnect the connection after sending the response

#
Channel
Analytic
Level
Error
Task
Userauthentication

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1294,
    "version": 0,
    "level": 2,
    "task": 7,
    "opcode": 0,
    "keywords": 2305843009213693964,
    "time_created": "2026-07-19T03:23:52.684300800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{bf440000-0bf1-0005-d91c-44bff10bdd01}"
    },
    "execution": {
      "process_id": 7308,
      "thread_id": 8480
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Sending HTTP 401 response to the client and disconnect the connection after sending the response "
}

Event ID 1295: User username authenticated successfully using authenticationMechanism authentication.

#
Channel
Analytic
Level
Informational
Task
Userauthentication

Message #

User %1 authenticated successfully using %2 authentication

Fields #

NameDescription
username UnicodeString
authenticationMechanism UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1295,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 0,
    "keywords": 2305843009213693964,
    "time_created": "2026-07-19T03:23:52.697001800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{bf440000-0bf1-0005-d91c-44bff10bdd01}"
    },
    "execution": {
      "process_id": 7308,
      "thread_id": 6836
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "authenticationMechanism": "NTLM",
    "username": "REDACTED\\grounding-user"
  },
  "message": "User REDACTED\\grounding-user authenticated successfully using NTLM authentication "
}

Event ID 1296: The authentication using client certificate with subject subject done successfully.

#
Channel
Analytic
Task
Userauthentication

Message #

The authentication using client certificate with subject %1 done successfully

Fields #

NameDescription
subject UnicodeString

Event ID 1297: Authenticating the user using authentication mechanism.

#
Channel
Analytic
Task
Userauthentication

Message #

Authenticating the user using %1 mechanism

Fields #

NameDescription
authentication UnicodeString

Event ID 1536: Authorizing the user

#
Channel
Analytic
Level
Informational
Task
Userauthorization

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 1536,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 0,
    "keywords": "0x200000000000000C",
    "time_created": "2026-06-02T05:32:28.992+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0009-EB78-7F8753F0DC01}"
    },
    "execution": {
      "process_id": 4672,
      "thread_id": 2972
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Task.Authorization"
}

Event ID 1537: The authorization of the user was done successfully

#
Channel
Analytic
Level
Informational
Task
Userauthorization

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1537,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 0,
    "keywords": 2305843009213693964,
    "time_created": "2026-07-19T03:23:52.697204600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{bf440000-0bf1-0005-d91c-44bff10bdd01}"
    },
    "execution": {
      "process_id": 7308,
      "thread_id": 6836
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The authorization of the user was done successfully "
}

Event ID 1538: The authorization of the user failed with error {errorCode}.

#
Channel
Analytic

Fields #

NameDescription
errorCode

Event ID 1792: The Winrm service is starting

#
Channel
Analytic

Event ID 1793: The Winrm service started successfully

#
Channel
Analytic

Event ID 1794: The WinRM service is unable to start because of a failure during initialization.

#
Channel
Analytic

Description

The WinRM service is unable to start because of a failure during initialization. The error code is {errorCode}.

Message #

The WinRM service is unable to start because of a failure during initialization. The error code is {errorCode}

Fields #

NameDescription
errorCode

Event ID 1795: The Winrm service is stopping

#
Channel
Analytic

Event ID 1796: The Winrm service was stopped successfully

#
Channel
Analytic

Event ID 1797: The WSMan service could not load current configuration settings as the settings are corrupted.

#
Channel
Analytic

Message #

The WSMan service could not load current configuration settings as the settings are corrupted. The service is started with default settings instead.  User Action  Use the following command to restore defaults:  winrm invoke Restore winrm/config @{}

Event ID 1798: The WSMan client could not load current configuration settings as the settings are corrupted.

#
Channel
Analytic

Message #

The WSMan client could not load current configuration settings as the settings are corrupted. The client is operating with default settings instead.  User Action  Start the WinRM service and use the following command to restore defaults:  winrm invoke Restore winrm/config @{}

Event ID 1799: The WSMan service failed to read configuration of the following plugin: {pluginName}.

#
Channel
Analytic

Message #

The WSMan service failed to read configuration of the following plugin:  {pluginName}. The error received was {errorcode}: %%{errorcode}  {errordetail}. User Action  Make sure this plugin configuration is valid.

Fields #

NameDescription
pluginName
errorcode
errordetail

Event ID 1808

#
Channel
Analytic

Description

{message}.

Message #

{message}

Fields #

NameDescription
message

Event ID 1840: An error was encountered while processing an operation.

#
Channel
Analytic
Level
Error
Task
WinrmOperation

Message #

An error was encountered while processing an operation.
Error Code: %1
Error String:%2

Fields #

NameDescription
errorCode UInt32
errorString UnicodeString
extraInformation1 UnicodeString
extraInformation2 UnicodeString
extraInformation3 UnicodeString
extraInformation4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{a7975c8f-ac13-49f1-87da-5a984a4ab417}",
    "event_source_name": "",
    "event_id": 1840,
    "version": 0,
    "level": 2,
    "task": 13,
    "opcode": 0,
    "keywords": 2305843009213694016,
    "time_created": "2026-07-19T03:23:52.684894600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{bf440000-0bf1-0001-217c-53bff10bdd01}"
    },
    "execution": {
      "process_id": 12308,
      "thread_id": 7320
    },
    "channel": "Microsoft-Windows-WinRM/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "errorCode": "2152992672",
    "errorString": "<f:WSManFault xmlns:f=\"http://schemas.microsoft.com/wbem/wsman/1/wsmanfault\" Code=\"2152992672\" Machine=\"GROUNDING-HOST\"><f:Message><f:ProviderFault provider=\"microsoft.powershell\" path=\"C:\\Windows\\system32\\pwrshplugin.dll\">PowerShell plugin operation is shutting down. This may happen if the hosting service or application is shutting down.</f:ProviderFault></f:Message></f:WSManFault>",
    "extraInformation1": "",
    "extraInformation2": "",
    "extraInformation3": "",
    "extraInformation4": ""
  },
  "message": "An error was encountered while processing an operation.\nError Code: 2152992672\nError String:<f:WSManFault xmlns:f=\"http://schemas.microsoft.com/wbem/wsman/1/wsmanfault\" Code=\"2152992672\" Machine=\"GROUNDING-HOST\"><f:Message><f:ProviderFault provider=\"microsoft.powershell\" path=\"C:\\Windows\\system32\\pwrshplugin.dll\">PowerShell plugin operation is shutting down. This may happen if the hosting service or application is shutting down.</f:ProviderFault></f:Message></f:WSManFault> "
}

Event ID 1841: An error was encountered while processing an operation.

#
Channel
Analytic
Task
WinrmOperation

Message #

An error was encountered while processing an operation.
Error Code: %1

Fields #

NameDescription
errorCode UInt32
extraInformation1 UnicodeString
extraInformation2 UnicodeString
extraInformation3 UnicodeString
extraInformation4 UnicodeString

Event ID 1842: Extra information.

#
Channel
Analytic
Task
WinrmOperation

Description

Extra information. Refer to the XML parameters for more details.

Message #

Extra information.  Refer to the XML parameters for more details.

Fields #

NameDescription
level UInt32
extraInformation1 UnicodeString
extraInformation2 UnicodeString
extraInformation3 UnicodeString
extraInformation4 UnicodeString

Event ID 1843: An unauthenticated connection from client clientIP is terminated.

#
Channel
Analytic
Task
Userauthentication

Message #

An unauthenticated connection from client %1 is terminated.

Fields #

NameDescription
clientIP UnicodeString

Event ID 2048: [Filename:- param1; Line:- param2; Function:- param3;] param4.

#
Channel
Debug
Task
WinrmVerboseMessage

Message #

[Filename:- %1; Line:- %2; Function:- %3;] %4

Fields #

NameDescription
param1 UnicodeString
param2 UInt32
param3 UnicodeString
param4 UnicodeString

Event ID 2049: [Filename:- param1; Line:- param2; Function:- param3; ErrorCode:- param4] param5.

#
Channel
Debug
Task
WinrmVerboseMessage

Message #

[Filename:- %1; Line:- %2; Function:- %3; ErrorCode:- %4] %5

Fields #

NameDescription
param1 UnicodeString
param2 UInt32
param3 UnicodeString
param4 UInt32
param5 UnicodeString

Event ID 10111: User authentication using Basic authentication scheme failed.

#
Channel
System
Level
3

Fields #

NameDescription
param1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "WinRM",
    "event_id": 10111,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-08 18:04:32.374695+00:00",
    "event_record_id": 2996,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "tel2-DC01-2022.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "param1": "1326"
  },
  "message": "User authentication using Basic authentication scheme failed. \n\n Additional Data \n Unexpected error received from LogonUser 1326: %%1326."
}

Event ID 10148: The WinRM service is listening for WS-Management requests

#
Channel
System
Level
Informational

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 10148,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:04.4490391+00:00",
    "event_record_id": 6770,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The WinRM service is listening for WS-Management requests. \r\n\r\n User Action \r\n Use the following command to see the specific IPs on which WinRM is listening: \r\n\r\n winrm enumerate winrm/config/listener"
}

Event ID 10149: The WinRM service is not listening for WS-Management requests

#
Channel
System
Level
Warning

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 10149,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:22:34.5179939+00:00",
    "event_record_id": 7362,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "The WinRM service is not listening for WS-Management requests. \r\n\r\n User Action \r\n If you did not intentionally stop the service, use the following command to see the WinRM configuration: \r\n\r\n winrm enumerate winrm/config/listener"
}

Event ID 10154: The WinRM service failed to create the following SPNs: spn1;

#
Channel
System
Level
Warning

Fields #

NameDescription
spn1
spn2
error

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "",
    "event_id": 10154,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:06.2146723+00:00",
    "event_record_id": 6776,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "spn1": "WSMAN/telemetry-DC-a.cell-a.ludus.domain",
    "spn2": "WSMAN/telemetry-DC-a",
    "error": "10054"
  },
  "message": "The WinRM service failed to create the following SPNs: WSMAN/telemetry-DC-a.cell-a.ludus.domain; WSMAN/telemetry-DC-a. \r\n\r\n Additional Data \r\n The error received was 10054: %%10054.\r\n\r\n User Action \r\n The SPNs can be created by an administrator using setspn.exe utility."
}

Event ID 468853: The WinRM service is not listening for requests since it failed to listen on at least one address and port.

#
Channel
Operational

Message #

The WinRM service is not listening for requests since it failed to listen on at least one address and port. 

 Remote management using WinRM will fail. 

 User Action 
 Configure listeners by enabling GPO policy for Auto Configuration of listeners or manually create a listener using WinRM command line tool.

Event ID 468854: The WinRM service is not listening for param1 requests because there was a failure binding to the URL (param2) in HTTP.

#
Channel
Operational

Description

The WinRM service is not listening for param1 requests because there was a failure binding to the URL (param2) in HTTP.SYS.

Message #

The WinRM service is not listening for %1 requests because there was a failure binding to the URL (%2) in HTTP.SYS. 

 Another process is registered to listen on the WinRM service URL prefix. 

 User Action 
 Correct this problem by stopping the other process, changing its URL prefix, or by changing the configuration for the WS-Management listening address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is not listening for
param2 UnicodeStringrequests because there was a failure binding to the URL (

Event ID 468855: The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.

#
Channel
Operational

Description

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (%1) in HTTP.SYS. 

 Another process is registered to listen on the WinRM client URL prefix. 

 User Action 
 Correct this problem by stopping the other process, changing its URL prefix, or by changing the configuration for the WS-Management listening address.

Fields #

NameDescription
param1 UnicodeStringThe WS-Management client is not listening for pushed events because there was a failure binding to the URL (

Event ID 468856: The WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (param1) in HTTP.

#
Channel
Operational

Description

The WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (%1) in HTTP.SYS.  

 No remote requests will be serviced on that URL. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys is %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys is

Event ID 468857: The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.

#
Channel
Operational

Description

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (%1) in HTTP.SYS. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys was %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WS-Management client is not listening for pushed events because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys was

Event ID 468862: The WinRM service cannot validate the client certificate because the revocation status of the certificate or one of the certificates in the certifi...

#
Channel
Operational

Description

The WinRM service cannot validate the client certificate because the revocation status of the certificate or one of the certificates in the certificate chain is either offline or stale.

Message #

The WinRM service cannot validate the client certificate because the revocation status of the certificate or one of the certificates in the certificate chain is either offline or stale. 

 User Action 
 Please ensure that the Certificate Revocation List is accessible and up-to-date.

Event ID 468863: User authentication using Basic authentication scheme failed.

#
Channel
Operational

Message #

User authentication using Basic authentication scheme failed. 

 Additional Data 
 Unexpected error received from LogonUser %1: %%%1.

Fields #

NameDescription
param1 UnicodeStringUnexpected error received from LogonUser

Event ID 468864: The client certificate exceeded the maximum size allowed by the WinRM service.

#
Channel
Operational

Message #

The client certificate exceeded the maximum size allowed by the WinRM service.

 User Action 
 Please use a different client certificate or a different authentication mechanism.

Event ID 468865: Request processing failed because the WinRM service cannot load data or event source: DLL="param1" User Action Please check if "param1" exists.

#
Channel
Operational

Description

Request processing failed because the WinRM service cannot load data or event source: DLL="param1".

Message #

Request processing failed because the WinRM service cannot load data or event source: DLL="%1" 

 User Action 
 Please check if "%1" exists. 

 Additional Data 
 Loading %1 failed with error="%2" (%%%2).

Fields #

NameDescription
param1 UnicodeStringRequest processing failed because the WinRM service cannot load data or event source: DLL="
param2 UnicodeStringfailed with error="

Event ID 468866: The SSL configuration for IP param1 and port param2 is shared with another service, such as Internet Information Services (IIS).

#
Channel
Operational

Message #

The SSL configuration for IP %1 and port %2 is shared with another service, such as Internet Information Services (IIS).

Fields #

NameDescription
param1 UnicodeStringThe SSL configuration for IP
param2 UnicodeStringand port

Event ID 468871: The WinRM service is unable to start because of a failure during initialization.

#
Channel
Operational

Message #

The WinRM service is unable to start because of a failure during initialization. 

 Additional Data 
 The error code is %1.

Fields #

NameDescription
param1 UnicodeStringThe error code is

Event ID 468872: The WinRM service has received an unsecure HTTP connection from param1.

#
Channel
Operational

Message #

The WinRM service has received an unsecure HTTP connection from %1. 

 This is not a secure configuration. 

 User Action 
 Set AllowUnencrypted to False in WinRM configuration to ensure packets are encrypted on the wire.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service has received an unsecure HTTP connection from

Event ID 468873: The WinRM service has been configured to accept basic authentication for unsecure HTTP connections.

#
Channel
Operational

Message #

The WinRM service has been configured to accept basic authentication for unsecure HTTP connections. 

 This is not a secure configuration. 

 User Action 
 Set AllowUnencrypted to False in WinRM configuration to ensure packets are encrypted on the wire.

Event ID 468880: The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (param1) in HTTP.

#
Channel
Operational

Description

The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (%1) in HTTP.SYS. 

 No remote requests will be serviced on that URL. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys is %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is not listening for HTTP requests because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys is

Event ID 468881: The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.

#
Channel
Operational

Description

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (%1) in HTTP.SYS. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys was %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WS-Management client is not listening for pushed events because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys was

Event ID 468882: IP Filter param1 specified in the GPO policy for Auto Configuration of listeners is invalid and it will be ignored.

#
Channel
Operational

Description

IP Filter param1 specified in the GPO policy for Auto Configuration of listeners is invalid and it will be ignored. Due to this issue, the WinRM service cannot use the autoconfigured listener.

Message #

IP Filter %1 specified in the GPO policy for Auto Configuration of listeners is invalid and it will be ignored. Due to this issue, the WinRM service cannot use the autoconfigured listener. 

 "*" is used to indicate that the service should listen on all available IPs on the machine. When "*" is used, other ranges cannot be specified in the filter. 

 User Action 
 Remove other IP ranges if "*" needs to be included in the IP Filter.

Fields #

NameDescription
param1 UnicodeStringIP Filter

Event ID 468883: The IP Range param1 is invalid and it will be ignored.

#
Channel
Operational

Message #

The IP Range %1 is invalid and it will be ignored.  

 Ranges are specified using the syntax IP1-IP2. Multiple ranges are separated using "," as delimiter. 
 Example IPv4 ranges:  2.0.0.1-2.0.0.20, 24.0.0.1-24.0.0.22 
Example IPv6 ranges:  3FFE:FFFF:7654:FEDA:1245:BA98:0000:0000-3FFE:FFFF:7654:FEDA:1245:BA98:3210:4562 

 User Action 
 Correct the IP filter %1 using the syntax described above.

Fields #

NameDescription
param1 UnicodeStringThe IP Range

Event ID 468884: The WinRM service is not listening for policy changes because there was a failure registering for changes to the contents of the WS-Management poli...

#
Channel
Operational

Description

The WinRM service is not listening for policy changes because there was a failure registering for changes to the contents of the WS-Management policy key.

Message #

The WinRM service is not listening for policy changes because there was a failure registering for changes to the contents of the WS-Management policy key. 

 No group policy change will be serviced. 

 User Action 
 Stop and restart the WinRM service. 

 Additional Data 
 The error code was %1.

Fields #

NameDescription
param1 UnicodeStringThe error code was

Event ID 468888: The WinRM service encountered a catastrophic security failure.

#
Channel
Operational

Description

The WinRM service encountered a catastrophic security failure. The service can no longer run under its security context.

Message #

The WinRM service encountered a catastrophic security failure. The service can no longer run under its security context. 

 User Action 
 Stop and restart the WinRM service. 

 Additional Data 
 The error code is %1.

Fields #

NameDescription
param1 UnicodeStringThe error code is

Event ID 468889: The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the IP address does not exist on the destination computer.

#
Channel
Operational

Description

The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the IP address does not exist on the destination computer. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with IP address %1 and Port %2 because the IP address does not exist on the destination computer. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct IP address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with IP address
param2 UnicodeStringand Port

Event ID 468890: The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the IP address param3 does not exist on the destination computer.

#
Channel
Operational

Description

The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the IP address param3 does not exist on the destination computer. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with Address %1 and Transport %2 because the IP address %3 does not exist on the destination computer. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct IP address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with Address
param2 UnicodeStringand Transport
param3 UnicodeStringbecause the IP address

Event ID 468891: The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the MAC address param3 does not exist on the destination computer.

#
Channel
Operational

Description

The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the MAC address param3 does not exist on the destination computer. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with IP address %1 and Port %2 because the MAC address %3 does not exist on the destination computer. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct MAC address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with IP address
param2 UnicodeStringand Port
param3 UnicodeStringbecause the MAC address

Event ID 468892: The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the MAC address param3 does not exist on the destination machine.

#
Channel
Operational

Description

The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the MAC address param3 does not exist on the destination machine. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with Address %1 and Transport %2 because the MAC address %3 does not exist on the destination machine. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct MAC address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with Address
param2 UnicodeStringand Transport
param3 UnicodeStringbecause the MAC address

Event ID 468893: The WinRM service cannot migrate the listener with IP address param1, Port param2 and Transport param3.

#
Channel
Operational

Description

The WinRM service cannot migrate the listener with IP address param1, Port param2 and Transport param3. A listener that has Address=param4 and Transport=param5 configuration already exists.

Message #

The WinRM service cannot migrate the listener with IP address %1, Port %2 and Transport %3. A listener that has Address=%4 and Transport=%5 configuration already exists.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with IP address
param2 UnicodeString, Port
param3 UnicodeStringand Transport
param4 UnicodeString. A listener that has Address=
param5 UnicodeStringand Transport=

Event ID 468894: The WinRM service cannot migrate the listener with Address param1 and Transport param2.

#
Channel
Operational

Description

The WinRM service cannot migrate the listener with Address param1 and Transport param2. A listener that has the same Address and Transport configuration already exists.

Message #

The WinRM service cannot migrate the listener with Address %1 and Transport %2. A listener that has the same Address and Transport configuration already exists.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with Address
param2 UnicodeStringand Transport

Event ID 468895: The WinRM service had a failure during migration.

#
Channel
Operational

Message #

The WinRM service had a failure during migration. 

 User Action 
 Create the configuration again using the WinRM command line tool. 

 Additional Data 
 The error code is: %1 %%%1

Fields #

NameDescription
param1 UnicodeStringThe error code is
param2 UnicodeString

Event ID 468896: The WinRM service had a failure reading the current configuration and is stopping.

#
Channel
Operational

Message #

The WinRM service had a failure reading the current configuration and is stopping. 

 User Action 
 Use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{} 

 Then add any custom configuration settings and restart the service. 

 Additional Data 
 The error code is: %1 %%%1

Fields #

NameDescription
param1 UnicodeStringThe error code is

Event ID 468897: The WinRM service had a failure applying the current configuration and is stopping.

#
Channel
Operational

Message #

The WinRM service had a failure applying the current configuration and is stopping. 

 User Action 
 Check for previous event log messages and restart the service.

Fields #

NameDescription
param1 UnicodeString

Event ID 468898: The WinRM service had a failure reading the current configuration and is stopping.

#
Channel
Operational

Message #

The WinRM service had a failure reading the current configuration and is stopping. 

 User Action 
 Use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{} 

 Then add any custom configuration settings and restart the service. 

 Additional Data 
 The error code is: %1 %%%1

Event ID 468899: The host name pattern "param1" is invalid and it will be ignored.

#
Channel
Operational

Description

The host name pattern "param1" is invalid and it will be ignored. Host name patterns must not be empty and they can contain at most one wildcard ("*"). "*" pattern can be used to indicate all hosts; if this pattern is used, no other pattern can show up in the list. Special string "<local>" can be used to indicate all host names that do not have a '.' User Action Correct the host name pattern using the syntax described above.

Message #

The host name pattern "%1" is invalid and it will be ignored. Host name patterns must not be empty and they can contain at most one wildcard ("*"). "*" pattern can be used to indicate all hosts; if this pattern is used, no other pattern can show up in the list. Special string "<local>" can be used to indicate all host names that do not have a '.'

 User Action 
 Correct the host name pattern using the syntax described above.

Fields #

NameDescription
param1 UnicodeStringThe host name pattern "

Event ID 468900: The WinRM service is listening for WS-Management requests.

#
Channel
Operational

Message #

The WinRM service is listening for WS-Management requests. 

 User Action 
 Use the following command to see the specific IPs on which WinRM is listening: 

 winrm enumerate winrm/config/listener

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "event_id": 10148,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T08:40:35.3663303+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {}
}

Event ID 468901: The WinRM service is not listening for WS-Management requests.

#
Channel
Operational

Message #

The WinRM service is not listening for WS-Management requests. 

 User Action 
 If you did not intentionally stop the service, use the following command to see the WinRM configuration: 

 winrm enumerate winrm/config/listener

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "event_id": 10149,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T15:32:28.3753201+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {}
}

Event ID 468902: The WinRM service could not use the following listener to receive WS-Management requests.

#
Channel
Operational

Description

The WinRM service could not use the following listener to receive WS-Management requests. The listener is enabled but the listener does not have an IP address configured.

Message #

The WinRM service could not use the following listener to receive WS-Management requests.  The listener is enabled but the listener does not have an IP address configured. 

 User Action 
 Check the underlying network configuration to determine if this listener has at least one valid IP. If the IP is valid, ensure that WinRM configuration does not exclude that IP address by using the following command: 

 winrm get winrm/config/service 

 Additional Data 
 Listener transport: %1 
 Listener address: %2

Fields #

NameDescription
transport UnicodeStringListener transport
address UnicodeStringListener address

Event ID 468903: The WinRM service had a failure (param1) reading configuration during ip address change notification.

#
Channel
Operational

Message #

The WinRM service had a failure (%1) reading configuration during ip address change notification. 

 Service will continue running with old configuration.

 User Action 
 If immediae changes are required manually restart the service

Fields #

NameDescription
param1 UnicodeStringThe WinRM service had a failure (

Event ID 468904: The WinRM service successfully processed an address change notification.

#
Channel
Operational

Event ID 468905: The WSMan IIS module failed to read configuration.

#
Channel
Operational

Description

The WSMan IIS module failed to read configuration. The error received was : %.

Message #

The WSMan IIS module failed to read configuration. The error received was %1: %%%1 
 %2.

 User Action 
 Make sure both the schema and validation files are present and valid.

Fields #

NameDescription
errorcode UnicodeStringThe WSMan IIS module failed to read configuration. The error received was
errordetail UnicodeString

Event ID 468906: The WinRM service failed to create the following SPNs: spn1; spn2.

#
Channel
Operational

Message #

The WinRM service failed to create the following SPNs: %1; %2. 

 Additional Data 
 The error received was %3: %%%3.

 User Action 
 The SPNs can be created by an administrator using setspn.exe utility.

Fields #

NameDescription
spn1 UnicodeStringThe WinRM service failed to create the following SPNs
spn2 UnicodeString
error UnicodeStringThe error received was

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "event_id": 10154,
    "level": "Warning",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-23T08:40:47.4200212+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "spn2": "WSMAN/JD-DC01-2022",
    "error": "1355",
    "spn1": "WSMAN/JD-DC01-2022.ludus.domain"
  }
}

Event ID 468907: The WSMan service failed to read configuration of the following plugin.

#
Channel
Operational

Message #

The WSMan service failed to read configuration of the following plugin: 
 %1. 

The error received was %2: %%%2 
 %3.

 User Action 
 Make sure this plugin configuration is valid.

Fields #

NameDescription
pluginName UnicodeString
errorcode UnicodeStringThe error received was
errordetail UnicodeString

Event ID 468908: The WinRM service failed to initialize CredSSP.

#
Channel
Operational

Message #

The WinRM service failed to initialize CredSSP. 

 Additional Data 
 The error received was %1.

 User Action 
 Configure CertificateThumbprint setting under the WinRM configuration for the service. Use the thumbprint of a valid certificate and make sure that Network Service has access to the private key of the certificate.

Fields #

NameDescription
error UnicodeStringThe error received was

Event ID 468909: The WinRM service received an error while trying to unloading a data or event source: DLL="param1" User Action Please check if there is an updated vers...

#
Channel
Operational

Description

The WinRM service received an error while trying to unloading a data or event source: DLL="param1".

Message #

The WinRM service received an error while trying to unloading a data or event source: DLL="%1" 

 User Action 
 Please check if there is an updated version of this file available: "%1". 

 Additional Data 
 Shutting down %1 failed with error="%2" (%%%2).

Fields #

NameDescription
param1 UnicodeStringThe WinRM service received an error while trying to unloading a data or event source: DLL="
param2 UnicodeStringfailed with error="

Event ID 468910: The WinRM service is listening on the default param1 port param2 and on param1 (Compatibility) port param3 for WS-Management requests.

#
Channel
Operational

Description

The WinRM service is listening on the default port and on (Compatibility) port for WS-Management requests. port is no longer the default port for the WinRM service.

Message #

The WinRM service is listening on the default %1 port %2 and on %1 (Compatibility) port %3 for WS-Management requests. %1 port %3 is no longer the default port for the WinRM service.

 If you want to disable the listener on the (Compatibility) port %3, run the following command:

 Winrm set winrm/config/service @{%4="False"}

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is listening on the default
param2 UnicodeString
param3 UnicodeString(Compatibility) port
param4 UnicodeStringWinrm set winrm/config/service @{

Event ID 468911: The WinRM service has terminated param1 unauthenticated connections over the past param2 minutes to maintain healthy system state.

#
Channel
Operational

Description

The WinRM service has terminated param1 unauthenticated connections over the past param2 minutes to maintain healthy system state. This will likely happen if the service is overloaded or if the service is under an authentication based attack. Action: Enable and observe Windows Remote Management Analytic log and look for warning events with Id 1843. These include additional information about the clients that got abruptly terminated.

Message #

The WinRM service has terminated %1 unauthenticated connections over the past %2 minutes to maintain healthy system state. This will likely happen if the service is overloaded or if the service is under an authentication based attack. 

 Action: 
Enable and observe Windows Remote Management Analytic log and look for warning events with Id 1843. These include additional information about the clients that got abruptly terminated.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service has terminated
param2 UnicodeStringunauthenticated connections over the past

Event ID 3221734403: The WinRM service is stopping because there was a failure registering for changes to the IP addresses.

#
Channel
Operational

Message #

The WinRM service is stopping because there was a failure registering for changes to the IP addresses. 

 User Action 
 Restart the WinRM service. 

 Additional Data 
 The error code was %1.

Fields #

NameDescription
param1 UnicodeString

Event ID 3221734404: The WinRM service is stopping because there was a failure registering for changes to the configuration.

#
Channel
Operational

Message #

The WinRM service is stopping because there was a failure registering for changes to the configuration. 

 User Action 
 Restart the WinRM service. 

 Additional Data 
 The error code was %1.

Fields #

NameDescription
param1 UnicodeString

Provenance

ETW provider GUID {A7975C8F-AC13-49F1-87DA-5A984A4AB417}

Defined in wsmres.dll, which carries the event manifest.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • JD-WIN11-22H2-1, sample captured from a live trace, binary version 10.0.22621.1, captured 2026-07-19

    Native ETL capture of an ordinary WSMan session and plugin lifecycle on the WinRM Analytic channel; identifiers were scrubbed in catalog examples.

  • JD-WIN11-22H2-1-expanded-20260719, sample captured from a live trace, binary version 10.0.22621.1, captured 2026-07-19

    Native ETL capture of localhost PowerShell remoting sessions, SOAP transfer, and WSMan operation completion; identifiers were scrubbed in catalog examples.