MsiInstaller

46 events across 1 channel

EventTitleChannelSample
1001Detection of product '%1', feature '%2' failed during request for component '%3'ApplicationN
1002Unexpected or missing value (name: '%1', value: '%2') in key '%3'ApplicationN
1003Unexpected or missing subkey '%1' in key '%2'ApplicationN
1004Detection of product '%1', feature '%2', component '%3' failed.ApplicationN
1005Install operation initiated a rebootApplicationY
1006Verification of the digital signature for cabinet '%1' cannot be performed.ApplicationN
1007The installation of %1 is not permitted by software restriction policy.ApplicationN
1008The installation of %1 is not permitted due to an error in software restriction …ApplicationN
1012This version of Windows does not support deploying 64-bit packages.ApplicationN
1013{Unhandled exception report}ApplicationN
1014Windows Installer proxy information not registered correctlyApplicationN
1015Failed to connect to server.ApplicationN
1016Detection of product '%1', feature '%2', component '%3' failed.ApplicationN
1017User SID had changed from '%1' to '%2' but the managed app and the user data …ApplicationN
1018The application '%1' cannot be installed because it is not compatible with this …ApplicationN
1019Product: %1 - Update '%2' was successfully removed.ApplicationN
1020Product: %1 - Update '%2' could not be removed.ApplicationN
1021Product: %1 - Update '%2' could not be removed.ApplicationN
1022Product: Microsoft .ApplicationY
1023Product: %1 - Update '%2' could not be installed.ApplicationN
1024Product: %1 - Update '%2' could not be installed.ApplicationN
1025Product: VMware Tools.ApplicationY
1026Windows Installer has determined that its configuration data registry key was …ApplicationN
1027Windows Installer has determined that a registry sub key %1 within its …ApplicationN
1028Windows Installer has determined that its configuration data cache folder was …ApplicationN
1029Product: VMware Tools.ApplicationY
1030Product attempted to install newer protected Windows fileApplicationN
1031Product assembly component in useApplicationN
1032An error occurred while refreshing environment variables updated during the …ApplicationY
1033Windows Installer installed the product.ApplicationY
1034Product: Data_0.ApplicationY
1035Windows Installer reconfigured the product.ApplicationY
1036Windows Installer installed an update.ApplicationY
1037Product update removal completedApplicationN
1038Windows Installer requires a system restart.ApplicationY
1040Beginning a Windows Installer transaction: %0ApplicationY
1042Ending a Windows Installer transaction: %0ApplicationY
1044%1 is not Microsoft signed.ApplicationN
10005The installer has encountered an unexpected error installing this package.ApplicationY
11704Product: VMware Tools -- Error 1704.ApplicationY
11707Product: Python 3.ApplicationY
11708Product [2] - Installation operation failedApplicationY
11724Event ID 11724ApplicationY
11728Product: Virtio-win-driver-installer -- Configuration completed successfully.ApplicationY
11729Event ID 11729ApplicationY
11925Event ID 11925ApplicationY

Event ID 1001: Detection of product '%1', feature '%2' failed during request for component '%3'

#
Provider
MsiInstaller
Channel
Application

Event ID 1002: Unexpected or missing value (name: '%1', value: '%2') in key '%3'

#
Provider
MsiInstaller
Channel
Application

Event ID 1003: Unexpected or missing subkey '%1' in key '%2'

#
Provider
MsiInstaller
Channel
Application

Event ID 1004: Detection of product '%1', feature '%2', component '%3' failed.

#
Provider
MsiInstaller
Channel
Application

Message #

Detection of product '%1', feature '%2', component '%3' failed. Note: Beginning with Windows Installer version 2.0, this message is: Detection of product '%1', feature '%2', component '%3' failed. The resource '%4' does not exist.

Event ID 1005: Install operation initiated a reboot

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1005,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2014-11-26T23:25:02.000000Z",
    "event_record_id": 1185,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": "S-1-5-21-3463664321-2923530833-3546627382-1000"
    }
  },
  "event_data": {}
}

References #

Event ID 1006: Verification of the digital signature for cabinet '%1' cannot be performed.

#
Provider
MsiInstaller
Channel
Application

Description

Verification of the digital signature for cabinet '%1' cannot be performed. WinVerifyTrust is not available on the computer.

Message #

Verification of the digital signature for cabinet '%1' cannot be performed. WinVerifyTrust is not available on the computer.

Event ID 1007: The installation of %1 is not permitted by software restriction policy.

#
Provider
MsiInstaller
Channel
Application

Message #

The installation of %1 is not permitted by software restriction policy. The Windows Installer only allows execution of unrestricted items. The authorization level returned by software restriction policy was %2.

Event ID 1008: The installation of %1 is not permitted due to an error in software restriction policy processing.

#
Provider
MsiInstaller
Channel
Application

Description

The installation of is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Message #

The installation of %1 is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Event ID 1012: This version of Windows does not support deploying 64-bit packages.

#
Provider
MsiInstaller
Channel
Application

Description

This version of Windows does not support deploying 64-bit packages. The script '%1' is for a 64-bit package.

Message #

This version of Windows does not support deploying 64-bit packages. The script '%1' is for a 64-bit package.

Event ID 1013: {Unhandled exception report}

#
Provider
MsiInstaller
Channel
Application

Event ID 1014: Windows Installer proxy information not registered correctly

#
Provider
MsiInstaller
Channel
Application

Event ID 1015: Failed to connect to server.

#
Provider
MsiInstaller
Channel
Application

Description

Failed to connect to server. Error: %d.

Message #

Failed to connect to server. Error: %d

Event ID 1016: Detection of product '%1', feature '%2', component '%3' failed.

#
Provider
MsiInstaller
Channel
Application

Description

Detection of product '%1', feature '%2', component '%3' failed. The resource '%4' in a run-from-source component could not be located because no valid and accessible source could be found.

Message #

Detection of product '%1', feature '%2', component '%3' failed. The resource '%4' in a run-from-source component could not be located because no valid and accessible source could be found.

Event ID 1017: User SID had changed from '%1' to '%2' but the managed app and the user data keys cannot be updated.

#
Provider
MsiInstaller
Channel
Application

Description

User SID had changed from '%1' to '%2' but the managed app and the user data keys cannot be updated. Error = '%3'.

Message #

User SID had changed from '%1' to '%2' but the managed app and the user data keys cannot be updated. Error = '%3'.

Event ID 1018: The application '%1' cannot be installed because it is not compatible with this version of Windows.

#
Provider
MsiInstaller
Channel
Application

Event ID 1019: Product: %1 - Update '%2' was successfully removed.

#
Provider
MsiInstaller
Channel
Application

Event ID 1020: Product: %1 - Update '%2' could not be removed.

#
Provider
MsiInstaller
Channel
Application

Description

Product: %1 - Update '%2' could not be removed. Error code %3. Additional information is available in the log file %4.

Message #

Product: %1 - Update '%2' could not be removed. Error code %3. Additional information is available in the log file %4.

Event ID 1021: Product: %1 - Update '%2' could not be removed.

#
Provider
MsiInstaller
Channel
Application

Description

Product: %1 - Update '%2' could not be removed. Error code %3.

Message #

Product: %1 - Update '%2' could not be removed. Error code %3.

Event ID 1022: Product: Microsoft .

#
Provider
MsiInstaller
Channel
Application
Level
Informational
Collection Priority
Recommended (NSA)

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1022,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2013-10-23T18:31:57+00:00",
    "event_record_id": 267,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": [
      "Microsoft .NET Framework 4 Client Profile",
      "KB2789642",
      "(NULL)",
      "(NULL)",
      "(NULL)",
      "(NULL)"
    ],
    "Binary": "ezNDMzkwMUM1LTM0NTUtM0UwQS1BMjE0LTBCMDkzQTUwNzBBNn0ge0I3QzIwRTE2LTlBM0EtM0YwNS1BNkI1LUUxNUFBMDkyMDBFMH0="
  },
  "message": "Product: Microsoft .NET Framework 4 Client Profile - Update 'KB2789642' installed successfully."
}

References #

Event ID 1023: Product: %1 - Update '%2' could not be installed.

#
Provider
MsiInstaller
Channel
Application

Description

Product: %1 - Update '%2' could not be installed. Error code %3. Additional information is available in the log file %4.

Message #

Product: %1 - Update '%2' could not be installed. Error code %3. Additional information is available in the log file %4.

Event ID 1024: Product: %1 - Update '%2' could not be installed.

#
Provider
MsiInstaller
Channel
Application

Description

Product: %1 - Update '%2' could not be installed. Error code %3.

Message #

Product: %1 - Update '%2' could not be installed. Error code %3.

Event ID 1025: Product: VMware Tools.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Description

Product: . The file is being used by the following process: Name: , Id .

Message #

Product: %1. The file %2 is being used by the following process: Name: %3, Id %4.

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:30:14.286069+00:00",
    "event_record_id": 1510,
    "correlation": {},
    "execution": {
      "process_id": 7244,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": [
      "VMware Tools",
      "C:\\Program Files\\VMware\\VMware Tools\\plugins\\vmsvc\\vmbackup.dll",
      "vmtoolsd",
      "3188",
      "(NULL)",
      "(NULL)"
    ],
    "Binary": "e0FGMTc0RTY0LTIyQ0YtNDM4Ni1BOUVDLTczRjI4NTczOTk5OH0="
  },
  "message": "Product: VMware Tools. The file C:\\Program Files\\VMware\\VMware Tools\\plugins\\vmsvc\\vmbackup.dll is being used by the following process: Name: vmtoolsd , Id 3188."
}

References #

Event ID 1026: Windows Installer has determined that its configuration data registry key was not secured properly.

#
Provider
MsiInstaller
Channel
Application

Message #

Windows Installer has determined that its configuration data registry key was not secured properly. The owner of the key must be either Local System or Builtin\Administrators. The existing key will be deleted and re-created with the appropriate security settings.

Event ID 1027: Windows Installer has determined that a registry sub key %1 within its configuration data was not secured properly.

#
Provider
MsiInstaller
Channel
Application

Message #

Windows Installer has determined that a registry sub key %1 within its configuration data was not secured properly. The owner of the key must be either Local System or Builtin\Administrators. The existing sub key and all of its contents will be deleted.

Event ID 1028: Windows Installer has determined that its configuration data cache folder was not secured properly.

#
Provider
MsiInstaller
Channel
Application

Message #

Windows Installer has determined that its configuration data cache folder was not secured properly. The owner of the key must be either Local System or Builtin\Administrators. The existing folder will be deleted and re-created with the appropriate security settings.

Event ID 1029: Product: VMware Tools.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Description

Product: . Restart required.

Message #

Product: %1. Restart required.

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1029,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:30:57.687962+00:00",
    "event_record_id": 1527,
    "correlation": {},
    "execution": {
      "process_id": 7244,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": [
      "VMware Tools",
      "(NULL)",
      "(NULL)",
      "(NULL)",
      "(NULL)",
      "(NULL)"
    ],
    "Binary": "e0FGMTc0RTY0LTIyQ0YtNDM4Ni1BOUVDLTczRjI4NTczOTk5OH0sIDMwMTA="
  },
  "message": "Product: VMware Tools. Restart required. The installation or update for the product required a restart for all changes to take effect.  The restart was deferred to a later time."
}

References #

Event ID 1030: Product attempted to install newer protected Windows file

#
Provider
MsiInstaller
Channel
Application

Message #

Product: %1. The application tried to install a more recent version of the protected Windows file %2. You may need to update your operating system for this application to work correctly. (Package Version: %3, Operating System Protected Version: %4).

Event ID 1031: Product assembly component in use

#
Provider
MsiInstaller
Channel
Application

Description

Product: %1. The assembly '%2' for component '%3' is in use.

Message #

Product: %1. The assembly '%2' for component '%3' is in use.

Event ID 1032: An error occurred while refreshing environment variables updated during the installation of 'Data_0'.

#
Provider
MsiInstaller
Channel
Application
Level
Warning

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1032,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-06T00:29:59.405233+00:00",
    "event_record_id": 1937,
    "correlation": {},
    "execution": {
      "process_id": 11432,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Data_0": "",
    "Data_1": "(NULL)",
    "Data_2": "(NULL)",
    "Data_3": "(NULL)",
    "Data_4": "(NULL)",
    "Data_5": "(NULL)",
    "Data_6": "",
    "Binary": ""
  },
  "message": ""
}

References #

Event ID 1033: Windows Installer installed the product.

#
Provider
MsiInstaller
Channel
Application
Level
Informational
Collection Priority
Recommended (NSA)

Description

Product: . Version: . Language: . Installation completed with status: . Manufacturer: .

Message #

Product: %1. Version: %2. Language: %3. Installation completed with status: %4. Manufacturer: %5.

Fields #

NameDescriptionRules
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Data1 detection rule
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1033,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-28T02:32:08.3090211+00:00",
    "event_record_id": 218,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
    }
  },
  "event_data": {
    "Data_0": "Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211",
    "Data_1": "14.44.35211",
    "Data_2": "1033",
    "Data_3": "0",
    "Data_4": "Microsoft Corporation",
    "Data_5": "(NULL)",
    "Data_6": ""
  },
  "message": "Windows Installer installed the product. Product Name: Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211. Product Version: 14.44.35211. Product Language: 1033. Manufacturer: Microsoft Corporation. Installation success or error status: 0."
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_NameeqMsiInstaller2 rulessigma

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Splunk # view in coverage

  • AteraAgent Installation - Windows (Windows Event Log) source: An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These remote monitoring and management (RMM) tools, such as AteraAgent,…

Event ID 1034: Product: Data_0.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Description

Product: Data_0. Version: Data_1. Language: Data_2. Removal completed with status: Data_3. Manufacturer: Data_4.

Message #

Product: %1. Version: %2. Language: %3. Removal completed with status: %4. Manufacturer: %5.

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1034,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-06T00:55:30.989129+00:00",
    "event_record_id": 1972,
    "correlation": {},
    "execution": {
      "process_id": 12792,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data_0": "Avira",
    "Data_1": "1.2.166.28430",
    "Data_2": "1033",
    "Data_3": "0",
    "Data_4": "Avira Operations GmbH & Co. KG",
    "Data_5": "(NULL)",
    "Data_6": "",
    "Binary": "7B36463131434143332D443333442D343336302D423133392D3733463332373641324239417D3030303032646464353631343830653530323239613162623366626534343539323961643030303030393034"
  },
  "message": ""
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_NameeqMsiInstaller1 rulesigma

References #

Event ID 1035: Windows Installer reconfigured the product.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Description

Product: . Version: . Language: . Configuration change completed with status: . Manufacturer: .

Message #

Product: %1. Version: %2. Language: %3. Configuration change completed with status: %4. Manufacturer: %5.

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1035,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2025-12-31T19:37:29.772246+00:00",
    "event_record_id": 135,
    "correlation": {},
    "execution": {
      "process_id": 6696,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Data": [
      "Virtio-win-driver-installer",
      "0.1.240",
      "1033",
      "0",
      "Red Hat, Inc.",
      "(NULL)"
    ],
    "Binary": "ezhDQUNCNjU3LTA4RTEtNDlEMS1BMTAwLUZCRUI3NTkxNTJFNX0wMDAwMDkzYjVmYjVmOGEwYjRhYTNjNzllNWI2MDRlYmQ4M2QwMDAwMDkwNA=="
  },
  "message": "Windows Installer reconfigured the product. Product Name: Virtio-win-driver-installer. Product Version: 0.1.240. Product Language: 1033. Manufacturer: Red Hat, Inc.. Reconfiguration success or error status: 0."
}

References #

Event ID 1036: Windows Installer installed an update.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Description

Product: . Version: . Language: . Update: . Update installation completed with status: . Manufacturer: .

Message #

Product: %1. Version: %2. Language: %3. Update: %4. Update installation completed with status: %5. Manufacturer: %6.

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1036,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2013-10-23T18:31:57+00:00",
    "event_record_id": 268,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": [
      "Microsoft .NET Framework 4 Client Profile",
      "4.0.30319",
      "0",
      "KB2789642",
      "0",
      "Microsoft Corporation"
    ],
    "Binary": "ezNDMzkwMUM1LTM0NTUtM0UwQS1BMjE0LTBCMDkzQTUwNzBBNn0wMDAwZDJlYmY0NjgzMWQyY2IzMjlhZjc2NzI5M2ViMjBjZmQwMDAwMDAwMA=="
  },
  "message": "Windows Installer installed an update. Product Name: Microsoft .NET Framework 4 Client Profile. Product Version: 4.0.30319. Product Language: 0. Manufacturer: Microsoft Corporation. Update Name: KB2789642. Installation success or error status: 0."
}

References #

Event ID 1037: Product update removal completed

#
Provider
MsiInstaller
Channel
Application

Description

Product: . Version: . Language: . Update: . Update removal completed with status: . Manufacturer: .

Message #

Product: %1. Version: %2. Language: %3. Update: %4. Update removal completed with status: %5. Manufacturer: %6.

Event ID 1038: Windows Installer requires a system restart.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Description

Product: . Version: . Language: . Reboot required. Reboot Type: . Reboot Reason: . Manufacturer: .

Message #

Product: %1. Version: %2. Language: %3. Reboot required. Reboot Type: %4. Reboot Reason: %5. Manufacturer: %6.

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1038,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:30:57.687221+00:00",
    "event_record_id": 1526,
    "correlation": {},
    "execution": {
      "process_id": 7244,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": [
      "VMware Tools",
      "12.3.0.22234872",
      "1033",
      "2",
      "1",
      "VMware, Inc."
    ],
    "Binary": "e0FGMTc0RTY0LTIyQ0YtNDM4Ni1BOUVDLTczRjI4NTczOTk5OH0wMDAwMDU3NWRlNDhkMWMwMDc0MzgxYmNjODViZDhmNzNlMDYwMDAwMDkwNA=="
  },
  "message": "Windows Installer requires a system restart. Product Name: VMware Tools. Product Version: 12.3.0.22234872. Product Language: 1033. Manufacturer: VMware, Inc.. Type of System Restart: 2. Reason for Restart: 1."
}

References #

Event ID 1040: Beginning a Windows Installer transaction: %0

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Fields #

NameDescriptionRules
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Data8 detection rules

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1040,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T13:56:24.8742908+00:00",
    "event_record_id": 736,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data_0": "{BDD79957-5801-4A2D-B09E-852E7FA64D01}",
    "Data_1": "3648",
    "Data_2": "(NULL)",
    "Data_3": "(NULL)",
    "Data_4": "(NULL)",
    "Data_5": "(NULL)",
    "Data_6": ""
  },
  "message": "Beginning a Windows Installer transaction: {BDD79957-5801-4A2D-B09E-852E7FA64D01}. Client Process Id: 3648."
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CommandLineis_not_null1 ruleelastic, kusto, splunk
CommandLinematch(?i)\w+tps?://\S+\.msi2 rulessplunk
Provider_NameeqMsiInstaller2 rulessigma
messagematch(?i)\w+tps?://\S+\.msi2 rulessplunk
signature_idcontains1040|10422 rulessplunk
signature_idcontains46882 rulessplunk
Datacontains\desktop\1 rulesigma
Datacontains\perflogs\1 rulesigma
Datacontains\users\public\1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Splunk # view in coverage

Event ID 1042: Ending a Windows Installer transaction: %0

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Data

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 1042,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T13:56:24.8899212+00:00",
    "event_record_id": 737,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data_0": "{BDD79957-5801-4A2D-B09E-852E7FA64D01}",
    "Data_1": "3648",
    "Data_2": "(NULL)",
    "Data_3": "(NULL)",
    "Data_4": "(NULL)",
    "Data_5": "(NULL)",
    "Data_6": ""
  },
  "message": "Ending a Windows Installer transaction: {BDD79957-5801-4A2D-B09E-852E7FA64D01}. Client Process Id: 3648."
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CommandLinematch(?i)\w+tps?://\S+\.msi2 rulessplunk
Provider_NameeqMsiInstaller2 rulessigma
messagematch(?i)\w+tps?://\S+\.msi2 rulessplunk
signature_idcontains1040|10422 rulessplunk
signature_idcontains46882 rulessplunk
Datacontains\desktop\1 rulesigma
Datacontains\perflogs\1 rulesigma
Datacontains\users\public\1 rulesigma

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Event ID 1044: %1 is not Microsoft signed.

#
Provider
MsiInstaller
Channel
Application

Description

is not Microsoft signed. So, rejecting per the Windows Lockdown Policy.

Message #

%1 is not Microsoft signed. So, rejecting per the Windows Lockdown Policy.

Event ID 10005: The installer has encountered an unexpected error installing this package.

#
Provider
MsiInstaller
Channel
Application
Level
Error

Description

The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is [1]. {{The arguments are: [2], [3], [4]}}.

Message #

The installer has encountered an unexpected error installing this package. This may indicate a problem with this package. The error code is [1]. {{The arguments are: [2], [3], [4]}}

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 10005,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-30T15:21:35.000000Z",
    "event_record_id": 1723,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": "S-1-5-21-3463664321-2923530833-3546627382-1000"
    }
  },
  "event_data": {}
}

References #

Event ID 11704: Product: VMware Tools -- Error 1704.

#
Provider
MsiInstaller
Channel
Application
Level
Error

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 11704,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:29:54.331227+00:00",
    "event_record_id": 1487,
    "correlation": {},
    "execution": {
      "process_id": 7244,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data": [
      "Product: VMware Tools -- Error 1704. An installation for VMware Tools is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?",
      "(NULL)",
      "(NULL)",
      "(NULL)",
      "(NULL)",
      "(NULL)"
    ],
    "Binary": "e0FGMTc0RTY0LTIyQ0YtNDM4Ni1BOUVDLTczRjI4NTczOTk5OH0="
  },
  "message": "Product: VMware Tools -- Error 1704. An installation for VMware Tools is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?"
}

References #

Event ID 11707: Product: Python 3.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 11707,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-28T02:32:08.3090211+00:00",
    "event_record_id": 217,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
    }
  },
  "event_data": {
    "Data_0": "Product: Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 -- Installation completed successfully.",
    "Data_1": "(NULL)",
    "Data_2": "(NULL)",
    "Data_3": "(NULL)",
    "Data_4": "(NULL)",
    "Data_5": "(NULL)",
    "Data_6": ""
  },
  "message": "Product: Microsoft Visual C++ 2022 X64 Additional Runtime - 14.44.35211 -- Installation completed successfully."
}

Event ID 11708: Product [2] - Installation operation failed

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 11708,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-30T15:21:37.000000Z",
    "event_record_id": 1724,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": "S-1-5-21-3463664321-2923530833-3546627382-1000"
    }
  },
  "event_data": {}
}

References #

Event ID 11724

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 11724,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-06T00:55:30.987658+00:00",
    "event_record_id": 1971,
    "correlation": {},
    "execution": {
      "process_id": 12792,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Data_0": "Product: Avira -- Removal completed successfully.",
    "Data_1": "(NULL)",
    "Data_2": "(NULL)",
    "Data_3": "(NULL)",
    "Data_4": "(NULL)",
    "Data_5": "(NULL)",
    "Data_6": "",
    "Binary": "7B36463131434143332D443333442D343336302D423133392D3733463332373641324239417D"
  },
  "message": ""
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_NameeqMsiInstaller1 rulesigma

References #

Event ID 11728: Product: Virtio-win-driver-installer -- Configuration completed successfully.

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 11728,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2025-12-31T19:37:29.771787+00:00",
    "event_record_id": 134,
    "correlation": {},
    "execution": {
      "process_id": 6696,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Data": [
      "Product: Virtio-win-driver-installer -- Configuration completed successfully.",
      "(NULL)",
      "(NULL)",
      "(NULL)",
      "(NULL)",
      "(NULL)"
    ],
    "Binary": "ezhDQUNCNjU3LTA4RTEtNDlEMS1BMTAwLUZCRUI3NTkxNTJFNX0="
  },
  "message": "Product: Virtio-win-driver-installer -- Configuration completed successfully."
}

References #

Event ID 11729

#
Provider
MsiInstaller
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 11729,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-18T16:33:01.000000Z",
    "event_record_id": 1434,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {}
}

References #

Event ID 11925

#
Provider
MsiInstaller
Channel
Application
Level
Error

Fields #

NameDescription
Data_0
Data_1
Data_2
Data_3
Data_4
Data_5
Data_6
Binary

Example Event #

{
  "system": {
    "provider": "MsiInstaller",
    "guid": "",
    "event_source_name": "",
    "event_id": 11925,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-02-11T01:36:24.136228+00:00",
    "event_record_id": 533,
    "correlation": {},
    "execution": {
      "process_id": 1800,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
    }
  },
  "event_data": {
    "Data_0": "Product: ScreenConnect Client (207d3896f8faaf5e) -- Error 1925. You do not have sufficient privileges to complete this installation for all users of the machine.  Log on as administrator and then retry this installation.",
    "Data_1": "(NULL)",
    "Data_2": "(NULL)",
    "Data_3": "(NULL)",
    "Data_4": "(NULL)",
    "Data_5": "(NULL)",
    "Data_6": "",
    "Binary": "7B37424537424331302D323733392D373944412D314642372D3231383934363230313145467D"
  },
  "message": ""
}