PowerShellCore

191 events across 4 channels

EventTitleChannelSample
4097ConnectTobeusedwhenoperationisjustexecutingamethod_V1ETW TraceN
4098ConnectTobeusedwhenoperationisjustexecutingamethod4098_V1ETW TraceN
4099ConnectTobeusedwhenoperationisjustexecutingamethod4099_V1ETW TraceN
4100NoneTobeusedwhenanexceptionisraised_V1OperationalN
4101NoneTobeusedwhenanexceptionisraised4101_V1OperationalN
4102NoneTobeusedwhenanexceptionisraised4102_V1OperationalN
4103NoneTobeusedwhenanexceptionisraised4103_V1OperationalN
4104Creating Scriptblock text (1 of 1): $global:?OperationalY
4105StartingCommandOpenOperationalN
4106StoppingCommandCloseOperationalN
7937NoneTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
7938NoneTobeusedwhenoperationisjustexecutingamethod7938_V1AnalyticN
7939NoneTobeusedwhenoperationisjustexecutingamethod7939_V1AnalyticN
7940NoneTobeusedwhenoperationisjustexecutingamethod7940_V1AnalyticN
7941task_0Tobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
7942NoneTobeusedwhenoperationisjustexecutingamethod7942_V1AnalyticN
8193ConnectOBEUSEDWHENANOBJECTISCONSTRUCTEDobeusedwhenanobjectisconstructed_V1OperationalN
8194ConnectOBEUSEDWHENANOBJECTISCONSTRUCTEDobeusedwhenanobjectisconstructed8194_V1OperationalN
8195ConnectOpenOperationalN
8196ConnectOpenOperationalN
8197ConnectOpenOperationalN
8198ConnectOpenOperationalN
12033ConnectTobeusedwhenoperationisjustexecutingamethod12033_V1AnalyticN
12034ConnectTobeusedwhenoperationisjustexecutingamethod12034_V1AnalyticN
12035ConnectTobeusedwhenoperationisjustexecutingamethod12035_V1AnalyticN
12036ConnectTobeusedwhenoperationisjustexecutingamethod12036_V1AnalyticN
12037ConnectTobeusedwhenoperationisjustexecutingamethod12037_V1AnalyticN
12038ConnectTobeusedwhenoperationisjustexecutingamethod12038_V1AnalyticN
12039ConnectOpenOperationalN
16385AmsiStateTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
16386WDACQueryTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
16387WDACAuditTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
24577PowerShellISEOperation_V1OperationalN
24578PowerShellISEOperation24578_V1OperationalN
24579PowerShellISEOperation24579_V1OperationalN
24580PowerShellISEOperation24580_V1OperationalN
24581PowerShellISEOperation24581_V1OperationalN
24582PowerShellISEOperation24582_V1OperationalN
24583PowerShellISEOperation24583_V1OperationalN
24584PowerShellISEOperation24584_V1OperationalN
24592PowerShellISEOperation24592_V1OperationalN
24593None_V1OperationalN
24594PowerShellISEOperation24594_V1OperationalN
24595PowerShellISEOperation24595_V1OperationalN
24596PowerShellISEOperation24596_V1OperationalN
24597PowerShellISEOperation24597_V1OperationalN
24598PowerShellISEOperation24598_V1OperationalN
24599PowerShellISEOperation24599_V1OperationalN
28673SerializeordeserializeremotingpayloadRehydration_V1AnalyticN
28674SerializeordeserializeremotingpayloadRehydration28674_V1AnalyticN
28675SerializeordeserializeremotingpayloadSerializationsettings_V1AnalyticN
28676SerializeordeserializeremotingpayloadSerializationsettings28676_V1AnalyticN
28677SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised_V1AnalyticN
28678SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28678_V1AnalyticN
28679SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28679_V1AnalyticN
28680SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28680_V1AnalyticN
28682SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28682_V1AnalyticN
28683SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28683_V1AnalyticN
28684SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28684_V1AnalyticN
32769task_0ReceiveAnalyticN
32775task_0OpenAnalyticN
32776task_0OpenAnalyticN
32777task_0OpenOperationalN
32784task_0OpenOperationalN
32785task_0ONNECTonnect_V1AnalyticN
32786task_0ONNECTonnect32786_V1AnalyticN
32787task_0Disconnect_V1AnalyticN
32788task_0Disconnect32788_V1AnalyticN
32789task_0SendAnalyticN
32790task_0SendAnalyticN
32791task_0ReceiveAnalyticN
32792task_0ReceiveAnalyticN
32793task_0ONNECTonnect32793_V1AnalyticN
32800task_0ONNECTonnect32800_V1AnalyticN
32801task_0Disconnect32801_V1AnalyticN
32802task_0Disconnect32802_V1AnalyticN
32803task_0Disconnect32803_V1AnalyticN
32804task_0Disconnect32804_V1AnalyticN
32805task_0ONNECTonnect32805_V1AnalyticN
32849task_0SendAnalyticN
32850task_0ONNECTonnect32850_V1AnalyticN
32851task_0ONNECTonnect32851_V1AnalyticN
32852task_0ONNECTonnect32852_V1AnalyticN
32853task_0ONNECTonnect32853_V1AnalyticN
32854task_0Disconnect32854_V1AnalyticN
32855task_0OpenAnalyticN
32856task_0OpenAnalyticN
32857task_0Disconnect32857_V1AnalyticN
32865task_0ONNECTonnect32865_V1AnalyticN
32866task_0ONNECTonnect32866_V1AnalyticN
32867task_0ReceiveAnalyticN
32868task_0SendAnalyticN
32869task_0Shuttingdown_V1AnalyticN
40961PowerShellConsoleStartupStart_V1OperationalY
40962PowerShellConsoleStartupStop_V1OperationalY
45057NoneTobeusedwhenanexceptionisraised45057_V1DebugN
45058NoneTobeusedwhenanexceptionisraised45058_V1DebugN
45059NoneTobeusedwhenoperationisjustexecutingamethod45059_V1DebugN
45060NoneTobeusedwhenoperationisjustexecutingamethod45060_V1DebugN
45061None45061_V1DebugN
45062NoneTobeusedwhenoperationisjustexecutingamethod45062_V1DebugN
45063WorkflowHostingTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
45064WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
45065WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45065_V1AnalyticN
45072WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45072_V1AnalyticN
45073WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45073_V1AnalyticN
45074WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45074_V1AnalyticN
45075WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45075_V1AnalyticN
45076WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45076_V1AnalyticN
45078WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45078_V1AnalyticN
45079WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45079_V1AnalyticN
45080WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45080_V1AnalyticN
45081WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45081_V1AnalyticN
45082WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45082_V1AnalyticN
45083WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45083_V1AnalyticN
45084WorkflowValidationTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
45085WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45085_V1AnalyticN
45086WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45086_V1AnalyticN
45087WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45087_V1AnalyticN
45088WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45088_V1AnalyticN
45089WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45089_V1AnalyticN
45090WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45090_V1AnalyticN
45091WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45091_V1AnalyticN
45092WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45092_V1AnalyticN
45093WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45093_V1AnalyticN
45094WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45094_V1AnalyticN
45095WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45095_V1AnalyticN
45096WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45096_V1AnalyticN
45097WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45097_V1AnalyticN
45098WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45098_V1AnalyticN
45100WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45100_V1AnalyticN
45101WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45101_V1AnalyticN
45102WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45102_V1AnalyticN
45104WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45104_V1AnalyticN
45105WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45105_V1AnalyticN
45106WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45106_V1AnalyticN
45107WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45107_V1AnalyticN
45108WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45108_V1AnalyticN
45109WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45109_V1AnalyticN
45110WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45110_V1AnalyticN
45111WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45111_V1AnalyticN
45112WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45112_V1AnalyticN
45113WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45113_V1AnalyticN
45114WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45114_V1AnalyticN
45115WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45115_V1AnalyticN
45116WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45116_V1AnalyticN
45117WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45117_V1AnalyticN
45118WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45118_V1AnalyticN
45119WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45119_V1AnalyticN
45120WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45120_V1AnalyticN
45121ConfigurationTobeusedwhenoperationisjustexecutingamethod_V1AnalyticN
45122ConfigurationTobeusedwhenoperationisjustexecutingamethod45122_V1AnalyticN
45123ConfigurationTobeusedwhenoperationisjustexecutingamethod45123_V1AnalyticN
45124ConfigurationTobeusedwhenoperationisjustexecutingamethod45124_V1AnalyticN
45125ConfigurationTobeusedwhenoperationisjustexecutingamethod45125_V1AnalyticN
45126WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45126_V1AnalyticN
45127WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45127_V1AnalyticN
45128WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45128_V1AnalyticN
45129None45129_V1DebugN
46337None46337_V1DebugN
46338None46338_V1DebugN
46339None46339_V1DebugN
46340None46340_V1DebugN
46341None46341_V1DebugN
46342None46342_V1DebugN
46343None46343_V1DebugN
46344None46344_V1DebugN
46345None46345_V1DebugN
46346None46346_V1DebugN
46347None46347_V1DebugN
46348None46348_V1DebugN
46349None46349_V1DebugN
46350None46350_V1DebugN
46351None46351_V1DebugN
46352None46352_V1DebugN
46353None46353_V1DebugN
46354None46354_V1DebugN
46355None46355_V1DebugN
46356None46356_V1DebugN
46357None46357_V1DebugN
46358None46358_V1OperationalN
49152None49152_V1DebugN
49153None49153_V1DebugN
53249PowerShellScheduledJobsTobeusedwhenoperationisjustexecutingamethod_V1OperationalN
53250PowerShellScheduledJobsTobeusedwhenoperationisjustexecutingamethod53250_V1OperationalN
53251PowerShellScheduledJobsTobeusedwhenanexceptionisraised_V1OperationalN
53504PowerShellNamedPipeIPCOpenOperationalY
53505PowerShellNamedPipeIPCCloseOperationalN
53506PowerShellNamedPipeIPCTobeusedwhenanexceptionisraised_V1OperationalN
53507PowerShellNamedPipeIPCONNECTonnect_V1OperationalN
53508PowerShellNamedPipeIPCCloseOperationalN

Event ID 4097: ConnectTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
ETW Trace
Task
CreateRunspace
Opcode
Method

Message #

Computer Name $null or . resolve to LocalHost

Event ID 4098: ConnectTobeusedwhenoperationisjustexecutingamethod4098_V1

#
Provider
PowerShellCore
Channel
ETW Trace
Task
CreateRunspace
Opcode
Method

Message #

Resolving to default scheme http

Event ID 4099: ConnectTobeusedwhenoperationisjustexecutingamethod4099_V1

#
Provider
PowerShellCore
Channel
ETW Trace
Task
CreateRunspace
Opcode
Method

Message #

Remote shell name resolved to default PowerShellCore

Event ID 4100: NoneTobeusedwhenanexceptionisraised_V1

#
Provider
PowerShellCore
Channel
Operational
Task
win:None
Opcode
Exception

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 4101: NoneTobeusedwhenanexceptionisraised4101_V1

#
Provider
PowerShellCore
Channel
Operational
Task
win:None
Opcode
Exception

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 4102: NoneTobeusedwhenanexceptionisraised4102_V1

#
Provider
PowerShellCore
Channel
Operational
Task
win:None
Opcode
Exception

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 4103: NoneTobeusedwhenanexceptionisraised4103_V1

#
Provider
PowerShellCore
Channel
Operational
Task
win:None
Opcode
Exception

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 4104: Creating Scriptblock text (1 of 1): $global:?

#
Provider
PowerShellCore
Channel
Operational
Level
Verbose
Task
CommandStart
Opcode
Create

Message #

Creating Scriptblock text (%1 of %2):__%3____ScriptBlock ID: %4__Path: %5

Fields #

NameDescription
MessageNumber
MessageTotal
ScriptBlockText
ScriptBlockId
Path

Example Event #

{
  "system": {
    "provider": "PowerShellCore",
    "guid": "{F90714A8-5509-434A-BF6D-B1624C8A19A2}",
    "event_source_name": "",
    "event_id": 4104,
    "version": 1,
    "level": 5,
    "task": 2,
    "opcode": 15,
    "keywords": 0,
    "time_created": "2026-05-30T04:29:54.7799039+00:00",
    "event_record_id": 30,
    "correlation": {
      "ActivityID": "{14429F51-EFE2-000D-01E6-4214E2EFDC01}"
    },
    "execution": {
      "process_id": 11980,
      "thread_id": 5976
    },
    "channel": "PowerShellCore/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "MessageNumber": "1",
    "MessageTotal": "1",
    "ScriptBlockText": "$global:?",
    "ScriptBlockId": "e76104e3-fb87-4091-ba9e-8ae27765de3e",
    "Path": ""
  },
  "message": "Creating Scriptblock text (1 of 1):\r\n$global:?\r\n\r\nScriptBlock ID: e76104e3-fb87-4091-ba9e-8ae27765de3e\r\nPath: "
}

Event ID 4105: StartingCommandOpen

#
Provider
PowerShellCore
Channel
Operational
Task
CommandStart
Opcode
Open

Message #

Started invocation of ScriptBlock ID: %1__Runspace ID: %2

Fields #

NameDescription
ScriptBlockId async)_V1(UnicodeString
RunspaceId UnicodeString

Event ID 4106: StoppingCommandClose

#
Provider
PowerShellCore
Channel
Operational
Task
CommandStop
Opcode
Close

Message #

Completed invocation of ScriptBlock ID: %1__Runspace ID: %2

Fields #

NameDescription
ScriptBlockId Async)_V1(UnicodeString
RunspaceId UnicodeString

Event ID 7937: NoneTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Method

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 7938: NoneTobeusedwhenoperationisjustexecutingamethod7938_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Method

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 7939: NoneTobeusedwhenoperationisjustexecutingamethod7939_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Method

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 7940: NoneTobeusedwhenoperationisjustexecutingamethod7940_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Method

Message #

%3____Context:__%1____User Data:__%2__

Fields #

NameDescription
ContextInfo UnicodeString
UserData UnicodeString
Payload UnicodeString

Event ID 7941: task_0Tobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Method

Message #

Correlating activity id's. __ _ CurrentActivityId: %1 __ _ ParentActivityId: %2

Fields #

NameDescription
currentActivityId GUID
parentActivityId GUID

Event ID 7942: NoneTobeusedwhenoperationisjustexecutingamethod7942_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Method

Message #

Class Name = %1__Method Name = %2__Workflow GUID = %3__Message = %4__%5__Activity Name = %6__Activity GUID = %7__Parameters = %8

Fields #

NameDescription
ClassName UnicodeString
MethodName UnicodeString
WorkflowGuid UnicodeString
Message UnicodeString
JobData UnicodeString
ActivityName UnicodeString
ActivityGuid UnicodeString
Parameters UnicodeString

Event ID 8193: ConnectOBEUSEDWHENANOBJECTISCONSTRUCTEDobeusedwhenanobjectisconstructed_V1

#
Provider
PowerShellCore
Channel
Operational
Task
CreateRunspace
Opcode
Constructor

Message #

Creating Runspace object __ _ Instance Id: %1

Fields #

NameDescription
param1 UnicodeString

Event ID 8194: ConnectOBEUSEDWHENANOBJECTISCONSTRUCTEDobeusedwhenanobjectisconstructed8194_V1

#
Provider
PowerShellCore
Channel
Operational
Task
CreateRunspace
Opcode
Constructor

Message #

Creating RunspacePool object __ _ InstanceId %1 __ _ MinRunspaces %2 __ _ MaxRunspaces %3

Fields #

NameDescription
InstanceId UnicodeString
MaxRunspaces UnicodeString
MinRunspaces UnicodeString

Event ID 8195: ConnectOpen

#
Provider
PowerShellCore
Channel
Operational
Task
CreateRunspace
Opcode
Open

Message #

Opening RunspacePool

Fields #

NameDescription
async)_V1(

Event ID 8196: ConnectOpen

#
Provider
PowerShellCore
Channel
Operational
Task
CreateRunspace
Opcode
Open

Message #

Modifying activity Id and correlating

Fields #

NameDescription
async)8196_V1(

Event ID 8197: ConnectOpen

#
Provider
PowerShellCore
Channel
Operational
Task
CreateRunspace
Opcode
Open

Message #

Runspace state changed to %1

Fields #

NameDescription
param1 async)8197_V1(UnicodeString

Event ID 8198: ConnectOpen

#
Provider
PowerShellCore
Channel
Operational
Task
CreateRunspace
Opcode
Open

Message #

Attempting session creation retry %1 for error code %2 on session Id %3

Fields #

NameDescription
param1 async)8198_V1(UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 12033: ConnectTobeusedwhenoperationisjustexecutingamethod12033_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
CreateRunspace
Opcode
Method

Message #

Port resolved to %1

Fields #

NameDescription
param1 UnicodeString

Event ID 12034: ConnectTobeusedwhenoperationisjustexecutingamethod12034_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
CreateRunspace
Opcode
Method

Message #

AppName resolved to %1

Fields #

NameDescription
param1 UnicodeString

Event ID 12035: ConnectTobeusedwhenoperationisjustexecutingamethod12035_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
CreateRunspace
Opcode
Method

Message #

ComputerName resolved to %1

Fields #

NameDescription
param1 UnicodeString

Event ID 12036: ConnectTobeusedwhenoperationisjustexecutingamethod12036_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
CreateRunspace
Opcode
Method

Message #

Scheme is %1

Fields #

NameDescription
param1 UnicodeString

Event ID 12037: ConnectTobeusedwhenoperationisjustexecutingamethod12037_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
CreateRunspace
Opcode
Method

Message #

Test analytic message

Event ID 12038: ConnectTobeusedwhenoperationisjustexecutingamethod12038_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
CreateRunspace
Opcode
Method

Message #

Connection Paramters are __ Connection URI: %1 __ Resource URI: %2 __ User: %3 __ OpenTimeout: %4 __ IdleTimeout: %5 __ CancelTimeout: %6 __ AuthenticationMechanism: %7 __ Thumb Print: %8 __ MaxUriRedirectionCount: %9 __ MaxReceivedDataSizePerCommand: %10 __ MaxReceivedObjectSize: %11

Fields #

NameDescription
uri UnicodeString
shell UnicodeString
userName UnicodeString
opentimeout UnicodeString
idletimeout UnicodeString
canceltimeout UnicodeString
auth UInt32
thumbPrint UnicodeString
redircount UnicodeString
recvdDataSize UnicodeString
recvdObjSize UnicodeString

Event ID 12039: ConnectOpen

#
Provider
PowerShellCore
Channel
Operational
Task
CreateRunspace
Opcode
Open

Message #

Modifying activity Id and correlating

Fields #

NameDescription
async)12039_V1(

Event ID 16385: AmsiStateTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Amsi
Opcode
Method

Message #

AmsiUtil state. __ _ state: %1 __ _ Context: %2

Fields #

NameDescription
Action UnicodeString
AmsiContext UnicodeString

Event ID 16386: WDACQueryTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WDAC
Opcode
Method

Message #

WDAC Query. __ _ Query: %1 __ _ File: %2 __ _ SuccessCode: %3 __ _ ResultCode: %4

Fields #

NameDescription
QueryName UnicodeString
FileName UnicodeString
QuerySuccess Int32
QuerySResult Int32

Event ID 16387: WDACAuditTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WDACAudit
Opcode
Method

Message #

WDAC Audit. __ _ Title: %1 __ _ Message: %2 __ _ FullyQualifiedId: %3

Fields #

NameDescription
Title UnicodeString
Message UnicodeString
FullyQualifiedId UnicodeString

Event ID 24577: PowerShellISEOperation_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE has started to run script file %1.

Fields #

NameDescription
FileName UnicodeString

Event ID 24578: PowerShellISEOperation24578_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE has started to run a user-selected script from file %1.

Fields #

NameDescription
FileName UnicodeString

Event ID 24579: PowerShellISEOperation24579_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is stopping the current command.

Event ID 24580: PowerShellISEOperation24580_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is resuming the debugger.

Event ID 24581: PowerShellISEOperation24581_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is stopping the debugger.

Event ID 24582: PowerShellISEOperation24582_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is stepping into debugging.

Event ID 24583: PowerShellISEOperation24583_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is stepping over debugging.

Event ID 24584: PowerShellISEOperation24584_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is stepping out of debugging.

Event ID 24592: PowerShellISEOperation24592_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is enabling all breakpoints.

Event ID 24593: None_V1

#
Provider
PowerShellCore
Channel
Operational
Task
win:None

Message #

Windows PowerShell ISE is disabling all breakpoints.

Event ID 24594: PowerShellISEOperation24594_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is removing all breakpoints.

Event ID 24595: PowerShellISEOperation24595_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is setting the breakpoint at line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24596: PowerShellISEOperation24596_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is removing the breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24597: PowerShellISEOperation24597_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is enabling the breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24598: PowerShellISEOperation24598_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE is disabling the breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 24599: PowerShellISEOperation24599_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ISEOperation

Message #

Windows PowerShell ISE has hit a breakpoint on line #: %1 of file %2.

Fields #

NameDescription
CurrentLine Int32
FileName UnicodeString

Event ID 28673: SerializeordeserializeremotingpayloadRehydration_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Rehydration

Message #

Successfully rehydrated an object. __ _ Deserialized type name: %1 __ _ Rehydrated by casting to type: %2 __ _ Rehydrated object is of type: %3

Fields #

NameDescription
DeserializedType UnicodeString
CastedToType UnicodeString
RehydratedType UnicodeString

Event ID 28674: SerializeordeserializeremotingpayloadRehydration28674_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Rehydration

Message #

Failed to rehydrated an object. __ _ Deserialized type name: %1 __ _ Rehydrated by casting to type: %2 __ _ Type cast exception: %3 __ _ Type cast inner exception: %4

Fields #

NameDescription
DeserializedType UnicodeString
CastedToType UnicodeString
TypeCastException UnicodeString
TypeCastInnerException UnicodeString

Event ID 28675: SerializeordeserializeremotingpayloadSerializationsettings_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
SerializationSettings

Message #

Serialization depth has been overriden. __ _ Serialized type name: %1 __ _ Original depth: %2 __ _ Overriden depth: %3 __ _ Current depth below top level: %4

Fields #

NameDescription
SerializedType UnicodeString
OriginalDepth Int32
OverridenDepth Int32
CurrentDepthBelowTopLevel Int32

Event ID 28676: SerializeordeserializeremotingpayloadSerializationsettings28676_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
SerializationSettings

Message #

Serialization mode has been overriden. __ _ Serialized type name: %1 __ _ Overriden mode: %2

Fields #

NameDescription
SerializedType UnicodeString
OverridenMode UInt32

Event ID 28677: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Exception

Message #

Serialization of a script property has been skipped, because there is no runspace to use for evaluation of the property. __ _ Property name: %1 __ _ Property owner's type name: %2 __ _ Getter script: %3

Fields #

NameDescription
PropertyName UnicodeString
PropertyOwnerType UnicodeString
GetterScript UnicodeString

Event ID 28678: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28678_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Exception

Message #

Serialization of a property has been skipped, because property getter failed. __ _ Property name: %1 __ _ Property owner's type name: %2 __ _ Exception from property getter: %3 __ _ Inner exception from property getter: %4

Fields #

NameDescription
PropertyName UnicodeString
PropertyOwnerType UnicodeString
Exception UnicodeString
InnerException UnicodeString

Event ID 28679: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28679_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Exception

Message #

Serialization of an enumerable object might not be complete, because object being enumerated threw an exception. __ _ Type of object being enumerated: %1 __ _ Exception: %2

Fields #

NameDescription
TypeBeingEnumerated UnicodeString
Exception UnicodeString

Event ID 28680: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28680_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Exception

Message #

Serialization called object's ToString method which failed. __ _ Type of object: %1 __ _ Exception: %2

Fields #

NameDescription
Type UnicodeString
Exception UnicodeString

Event ID 28682: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28682_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Exception

Message #

Maximum depth below top level has been reached, forcing object to be serialized as strings. __ _ Object type at max depth: %1 __ _ Property name at max depth: %2 __ _ Depth: %3

Fields #

NameDescription
TypeOfObjectAtMaxDepth UnicodeString
PropertyNameAtMaxDepth UnicodeString
Depth Int32

Event ID 28683: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28683_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Exception

Message #

XmlException has been thrown by the deserializer (most likely indicating incorrect clixml format). __ _ Line number: %1 Line position: %2 __ _ Exception: %3

Fields #

NameDescription
LineNumber Int32
LinePosition Int32
Exception UnicodeString

Event ID 28684: SerializeordeserializeremotingpayloadTobeusedwhenanexceptionisraised28684_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Serialization
Opcode
Exception

Message #

Serialization of specified properties failed, because one of the specified properties was missing. __ _ Type of object: %1 __ _ Property name: %2

Fields #

NameDescription
TypeOfObjectWithMissingProperty UnicodeString
PropertyName UnicodeString

Event ID 32769: task_0Receive

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Receive

Message #

Received object with Runspace Id: %1 Command Id: %2 Destination: %3 DataType: %4 TargetInterface: %5

Fields #

NameDescription
Runspace_InstanceId Async)_V1(UnicodeString
PowerShell_InstanceId UnicodeString
Destination UInt32
DataType UInt32
TargetInterface UInt32

Event ID 32775: task_0Open

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Open

Message #

An unhandled exception occurred in the appdomain. __Exception Type: %1 __Exception Message: %2 __Exception StackTrace: %3

Fields #

NameDescription
param1 async)_V1(UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32776: task_0Open

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Open

Message #

Runspace Id: %1 Pipeline Id: %2. WSMan reported an error with error code: %3. __ Error message: %4 __ StackTrace: %5

Fields #

NameDescription
SessionId async)32776_V1(UnicodeString
PipelineId UnicodeString
ErrorCode UnicodeString
ErrorMessage UnicodeString
StackTrace UnicodeString

Event ID 32777: task_0Open

#
Provider
PowerShellCore
Channel
Operational
Task
win:None
Opcode
Open

Message #

An unhandled exception occurred in the appdomain. __Exception Type: %1 __Exception Message: %2 __Exception StackTrace: %3

Fields #

NameDescription
param1 async)32777_V1(UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32784: task_0Open

#
Provider
PowerShellCore
Channel
Operational
Task
win:None
Opcode
Open

Message #

Runspace Id: %1 Pipeline Id: %2. WSMan reported an error with error code: %3. __ Error message: %4 __ StackTrace: %5

Fields #

NameDescription
SessionId async)32784_V1(UnicodeString
PipelineId UnicodeString
ErrorCode UnicodeString
ErrorMessage UnicodeString
StackTrace UnicodeString

Event ID 32785: task_0ONNECTonnect_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Runspace Id %1. Establishing a connection using WSMan Create Shell

Fields #

NameDescription
param1 UnicodeString

Event ID 32786: task_0ONNECTonnect32786_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Runspace Id %1. Callback received for WSMan Create Shell

Fields #

NameDescription
param1 UnicodeString

Event ID 32787: task_0Disconnect_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Runspace Id: %1. Closing shell using WSManCloseShell

Fields #

NameDescription
param1 UnicodeString

Event ID 32788: task_0Disconnect32788_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Runspace Id: %1. Callback received for WSManCloseShell

Fields #

NameDescription
param1 UnicodeString

Event ID 32789: task_0Send

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Send

Message #

Runspace Id: %1 Pipeline Id: %2. Sending data of size %3

Fields #

NameDescription
SessionId Async)_V1(UnicodeString
PipelineId UnicodeString
DataSize UnicodeString

Event ID 32790: task_0Send

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Send

Message #

Runspace Id: %1 Pipeline Id: %2. Callback received for WSManSendShellInputEx

Fields #

NameDescription
SessionId Async)32790_V1(UnicodeString
PipelineId UnicodeString

Event ID 32791: task_0Receive

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Receive

Message #

Runspace Id: %1 Pipeline Id: %2. Placing Receive request using WSManReceiveShellOutputEx

Fields #

NameDescription
SessionId Async)32791_V1(UnicodeString
PipelineId UnicodeString

Event ID 32792: task_0Receive

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Receive

Message #

Runspace Id: %1 Pipeline Id: %2. Received Data of size %3.

Fields #

NameDescription
SessionId Async)32792_V1(UnicodeString
PipelineId UnicodeString
DataSize UnicodeString

Event ID 32793: task_0ONNECTonnect32793_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Runspace Id %1 Pipeline Id %2. Establishing a command connection using WSManRunShellCommandEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Event ID 32800: task_0ONNECTonnect32800_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Runspace Id %1 Pipeline Id %2. Callback received for command connection

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Event ID 32801: task_0Disconnect32801_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Runspace Id: %1 Pipeline Id %2. Closing transport for command

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Event ID 32802: task_0Disconnect32802_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Runspace Id: %1 Pipeline Id %2. Callback received for command close

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Event ID 32803: task_0Disconnect32803_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Runspace Id: %1 Pipeline Id %2. Sending signal with code %3 using WSManSignalShellEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString
SignalCode UnicodeString

Event ID 32804: task_0Disconnect32804_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Runspace Id: %1 Pipeline Id %2. Callback received for WSManSignalShellEx

Fields #

NameDescription
SessionId UnicodeString
PipelineId UnicodeString

Event ID 32805: task_0ONNECTonnect32805_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Runspace Id: %1. Connection is getting redirected to Uri: %2

Fields #

NameDescription
SessionId UnicodeString
Uri UnicodeString

Event ID 32849: task_0Send

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Send

Message #

Runspace Id: %1 Pipeline Id: %2. Server is sending data of size %3 to client. DataType: %4 TargetInterface: %5

Fields #

NameDescription
Runspace_InstanceId Async)32849_V1(UnicodeString
PowerShell_InstanceId UnicodeString
DataSize UnicodeString
DataType UInt32
TargetInterface UInt32

Event ID 32850: task_0ONNECTonnect32850_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Request %1. Creating a server remote session. UserName: %2 Custom Shell Id: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32851: task_0ONNECTonnect32851_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Reporting context for request: %1 Context Reported: %1

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 32852: task_0ONNECTonnect32852_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Reporting operation complete for request: %1 __ Error Code: %2 __ Error Message: %3 __ StackTrace: %4

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 32853: task_0ONNECTonnect32853_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Shell Context %1. Request Id %2. Creating a commonad session for running a command.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 32854: task_0Disconnect32854_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Shell Context %1 Command Context %2 Request Id %3. Stopping command.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32855: task_0Open

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Open

Message #

Shell Context %1 Command Context %2 Request Id %3. Received data from client.

Fields #

NameDescription
param1 async)32855_V1(UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32856: task_0Open

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Open

Message #

Shell Context %1 Command Context %2 Request Id %3. Client sent a receive request so that server can send data.

Fields #

NameDescription
param1 async)32856_V1(UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32857: task_0Disconnect32857_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Disconnect

Message #

Shell Context %1 Command Context %2 IsReceiveOperation %3. Got close operation request.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 32865: task_0ONNECTonnect32865_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Loading assembly %1 for custom shell with shell Id %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 32866: task_0ONNECTonnect32866_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Connect

Message #

Loading type %1 for custom shell with shell Id %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 32867: task_0Receive

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Receive

Message #

Received remoting fragment. __ _ Object Id: %1 __ _ Fragment Id: %2 __ _ Start Flag: %3 __ _ End Flag: %4 __ _ Payload Length: %5 __ _ Payload Data: %6

Fields #

NameDescription
ObjectId Async)32867_V1(Int64
FragmentId Int64
sFlag Int32
eFlag Int32
FragmentLength UInt32
FragmentPayload UnicodeString

Event ID 32868: task_0Send

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
Send

Message #

Sent remoting fragment. __ _ Object Id: %1 __ _ Fragment Id: %2 __ _ Start Flag: %3 __ _ End Flag: %4 __ _ Payload Length: %5 __ _ Payload Data: %6

Fields #

NameDescription
ObjectId Async)32868_V1(Int64
FragmentId Int64
sFlag Int32
eFlag Int32
FragmentLength UInt32
FragmentPayload UnicodeString

Event ID 32869: task_0Shuttingdown_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
win:None
Opcode
ShuttingDown

Message #

Shutting down winrm service.

Event ID 40961: PowerShellConsoleStartupStart_V1

#
Provider
PowerShellCore
Channel
Operational
Level
Informational
Task
Powershell-Console-Startup
Opcode
Start

Message #

PowerShell console is starting up

Example Event #

{
  "system": {
    "provider": "PowerShellCore",
    "guid": "F90714A8-5509-434A-BF6D-B1624C8A19A2",
    "event_source_name": "",
    "event_id": 40961,
    "version": 1,
    "level": 4,
    "task": 4,
    "opcode": 1,
    "keywords": 0,
    "time_created": "2023-11-06T01:36:38.224978+00:00",
    "event_record_id": 13,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-E00D-EEE43710DA01"
    },
    "execution": {
      "process_id": 20676,
      "thread_id": 8100
    },
    "channel": "PowerShellCore/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 40962: PowerShellConsoleStartupStop_V1

#
Provider
PowerShellCore
Channel
Operational
Level
Informational
Task
Powershell-Console-Startup
Opcode
Stop

Message #

PowerShell console is ready for user input

Example Event #

{
  "system": {
    "provider": "PowerShellCore",
    "guid": "F90714A8-5509-434A-BF6D-B1624C8A19A2",
    "event_source_name": "",
    "event_id": 40962,
    "version": 1,
    "level": 4,
    "task": 4,
    "opcode": 2,
    "keywords": 0,
    "time_created": "2023-11-06T01:36:44.837777+00:00",
    "event_record_id": 15,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0001-E00D-EEE43710DA01"
    },
    "execution": {
      "process_id": 20676,
      "thread_id": 8100
    },
    "channel": "PowerShellCore/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 45057: NoneTobeusedwhenanexceptionisraised45057_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None
Opcode
Exception

Message #

Tracing ErrorRecord: __ Message: %1 __ CategoryInfo.Category: %2 __ CategoryInfo.Reason : %3 __ CategoryInfo.TargetName : %4 __ FullyQualifiedErrorId: %5 __ Exception Details: __ Message : %6 __ Stack Trace: %7 __ InnerException %8 __

Fields #

NameDescription
Message UnicodeString
Category UnicodeString
Reason UnicodeString
TargetName UnicodeString
FullyQualifiedErrorId UnicodeString
ExceptionMessage UnicodeString
ExceptionStackTrace UnicodeString
ExceptionInnerException UnicodeString

Event ID 45058: NoneTobeusedwhenanexceptionisraised45058_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None
Opcode
Exception

Message #

Exception: __ Message: %1 __ StackTrace: %2 __ InnerException : %3 __

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 45059: NoneTobeusedwhenoperationisjustexecutingamethod45059_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None
Opcode
Method

Message #

Tracing PSObject

Event ID 45060: NoneTobeusedwhenoperationisjustexecutingamethod45060_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None
Opcode
Method

Message #

Tracing Job: __ Id: %1 __ InstanceId: %2 __ Name: %3 __ Location: %4 __ State: %5 __ Command: %6 __

Fields #

NameDescription
Id UnicodeString
InstanceId UnicodeString
Name UnicodeString
Location UnicodeString
State UnicodeString
Command UnicodeString

Event ID 45061: None45061_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

Trace Information: __ %1

Fields #

NameDescription
param1 UnicodeString

Event ID 45062: NoneTobeusedwhenoperationisjustexecutingamethod45062_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None
Opcode
Method

Message #

Connection Paramters are __ Connection URI: %1 __ Resource URI: %2 __ User: %3 __ OpenTimeout: %4 __ IdleTimeout: %5 __ CancelTimeout: %6 __ AuthenticationMechanism: %7 __ Thumb Print: %8 __ MaxUriRedirectionCount: %9 __ MaxReceivedDataSizePerCommand: %10 __ MaxReceivedObjectSize: %11

Fields #

NameDescription
uri UnicodeString
shell UnicodeString
userName UnicodeString
opentimeout UnicodeString
idletimeout UnicodeString
canceltimeout UnicodeString
auth UInt32
thumbPrint UnicodeString
redircount UnicodeString
recvdDataSize UnicodeString
recvdObjSize UnicodeString

Event ID 45063: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowHosting
Opcode
Method

Message #

Workflow plugin loaded. __ _ EndpointName: %1 __ _ User: %2 __ _ HostingMode: %3 __ _ Protocol: %4 __ _ Configuration: __ %5

Fields #

NameDescription
endpointName UnicodeString
user UnicodeString
hostingMode UnicodeString
protocol UnicodeString
configuration UnicodeString

Event ID 45064: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow execution started. __ _ WorkflowId: %1 __ _ ManagedNodes: %2

Fields #

NameDescription
workflowId GUID
managedNodes UnicodeString

Event ID 45065: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45065_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow state changed. __ _ WorkflowId: %1 __ _ NewState: %2 __ _ OldState: %3

Fields #

NameDescription
workflowId GUID
newState UnicodeString
oldState UnicodeString

Event ID 45072: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45072_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowHosting
Opcode
Method

Message #

Workflow plugin has been requested for a shutdown. __ _ EndpointName: %1

Fields #

NameDescription
endpointName UnicodeString

Event ID 45073: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45073_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowHosting
Opcode
Method

Message #

Workflow plugin restarted. __ _ EndpointName: %1

Fields #

NameDescription
endpointName UnicodeString

Event ID 45074: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45074_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow is resuming. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45075: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45075_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

A quota limit that was set for the endpoint was exceeded. __ _ EndpointName: %1 __ _ ConfigName: %2 __ _ AllowedValue: %3 __ _ ValueInQuestion: %4

Fields #

NameDescription
endpointName UnicodeString
configName UnicodeString
allowedValue UnicodeString
valueInQuestion UnicodeString

Event ID 45076: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45076_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow has resumed. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45078: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45078_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow runspace pool was created. __ _ WorkflowId: %1 __ _ ManagedNode: %2

Fields #

NameDescription
workflowId GUID
managedNode UnicodeString

Event ID 45079: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45079_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Activity was queued for execution. __ _ WorkflowId: %1 __ _ ActivityName: %2

Fields #

NameDescription
workflowId GUID
activityName UnicodeString

Event ID 45080: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45080_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Activity execution started. __ _ ActivityName: %1 __ _ ActivityTypeName: %2

Fields #

NameDescription
activityName UnicodeString
activityTypeName UnicodeString

Event ID 45081: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45081_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow is being imported from a XAML file. __ _ WorkflowId: %1 __ _ XamlFile: %2

Fields #

NameDescription
workflowId GUID
xamlFile UnicodeString

Event ID 45082: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45082_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow has been imported from a XAML file. __ _ WorkflowId: %1 __ _ XamlFile: %2

Fields #

NameDescription
workflowId GUID
xamlFile UnicodeString

Event ID 45083: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45083_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow could not be imported from a XAML file because of an error. __ _ WorkflowId: %1 __ _ ErrorDescription: %2

Fields #

NameDescription
workflowId GUID
errorDescription UnicodeString

Event ID 45084: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowValidation
Opcode
Method

Message #

Workflow validation started. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45085: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45085_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowValidation
Opcode
Method

Message #

Workflow validation succeeded. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45086: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45086_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowValidation
Opcode
Method

Message #

Workflow validation failed with error. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45087: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45087_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow activity validated. __ _ WorkflowId: %1 __ _ ActivityDisplayName: %2 __ _ ActivityTypeName: %3

Fields #

NameDescription
workflowId GUID
activityDisplayName UnicodeString
activityType UnicodeString

Event ID 45088: WorkflowValidationTobeusedwhenoperationisjustexecutingamethod45088_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowValidation
Opcode
Method

Message #

Workflow activity could not be validated. __ _ WorkflowId: %1 __ _ ActivityDisplayName: %2 __ _ ActivityTypeName: %3

Fields #

NameDescription
workflowId GUID
activityDisplayName UnicodeString
activityType UnicodeString

Event ID 45089: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45089_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Activity execution failed. __ _ WorkflowId: %1 __ _ ActivityName: %2 __ _ FailureDescription: %3

Fields #

NameDescription
workflowId GUID
activityName UnicodeString
failureDescription UnicodeString

Event ID 45090: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45090_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Runspace availability changed. __ _ RunspaceId: %1 __ _ Availability: %2

Fields #

NameDescription
runspaceId UnicodeString
availability UnicodeString

Event ID 45091: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45091_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Runspace state changed. __ _ RunspaceId: %1 __ _ NewState: %2 __ _ OldState: %3

Fields #

NameDescription
runspaceId UnicodeString
newState UnicodeString
oldState UnicodeString

Event ID 45092: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45092_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow loaded for execution. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45093: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45093_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow unloaded. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45094: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45094_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow execution cancelled. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45095: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45095_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow execution aborted. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45096: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45096_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow cleanup operation executed. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45097: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45097_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Persisted workflow loaded from disk. __ _ WorkflowId: %1 __ _ Path: %2

Fields #

NameDescription
workflowId GUID
path UnicodeString

Event ID 45098: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45098_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow data was deleted from disk. __ _ WorkflowId: %1 __ _ Path: %2

Fields #

NameDescription
workflowId GUID
path UnicodeString

Event ID 45100: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45100_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Starting remove job. __ _ JobId: %1

Fields #

NameDescription
jobId GUID

Event ID 45101: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45101_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Job state changed. __ _ JobId: %1 __ _ WorkflowId: %2 __ _ NewState: %3 __ _ OldState: %4

Fields #

NameDescription
jobId Int32
workflowId GUID
newState UnicodeString
oldState UnicodeString

Event ID 45102: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45102_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Job error. __ _ JobId: %1 __ _ WorkflowId: %2 __ _ ErrorDescription: %3

Fields #

NameDescription
jobId Int32
workflowId GUID
errorDescription UnicodeString

Event ID 45104: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45104_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Job created for workflow (child job). __ _ ParentJobId: %1 __ _ ChildJobId: %2 __ _ ChildWorkflowId: %3

Fields #

NameDescription
parentJobId GUID
childJobId GUID
childWorkflowId GUID

Event ID 45105: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45105_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Parent job created for workflow. __ _ JobId: %1

Fields #

NameDescription
jobId GUID

Event ID 45106: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45106_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

All required jobs were created for workflow execution. __ _ JobId: %1 __ _ WorkflowId: %2

Fields #

NameDescription
jobId GUID
workflowId GUID

Event ID 45107: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45107_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Child job removed for workflow. __ _ ParentJobId: %1 __ _ ChildJobId: %2 __ _ WorkflowId: %3

Fields #

NameDescription
parentJobId GUID
childJobId GUID
workflowId GUID

Event ID 45108: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45108_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

An error occurred while removing job. __ _ ParentJobId: %1 __ _ ChildJobId: %2 __ _ WorkflowId: %3 __ _ Error: %4

Fields #

NameDescription
parentJobId GUID
childJobId GUID
workflowId GUID
error UnicodeString

Event ID 45109: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45109_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Loading workflow for execution. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45110: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45110_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow execution finished. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45111: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45111_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Cancelling workflow execution. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45112: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45112_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Aborting workflow execution. __ _ WorkflowId: %1 __ _ Reason: %2

Fields #

NameDescription
workflowId GUID
reason UnicodeString

Event ID 45113: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45113_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Unloading workflow. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45114: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45114_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Forced workflow shutdown started. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45115: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45115_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Forced workflow shutdown finished. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45116: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45116_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

An error occurred while forcefully shutting down a workflow. __ _ WorkflowId: %1 __ _ ErrorDescription: %2

Fields #

NameDescription
workflowId GUID
errorDescription UnicodeString

Event ID 45117: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45117_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Persisting workflow to disk. __ _ WorkflowId: %1 __ _ PersistPath: %2

Fields #

NameDescription
workflowId GUID
persistPath UnicodeString

Event ID 45118: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45118_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow persisted to disk. __ _ WorkflowId: %1

Fields #

NameDescription
workflowId GUID

Event ID 45119: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45119_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Activity execution finished. __ _ ActivityName: %1

Fields #

NameDescription
activityName UnicodeString

Event ID 45120: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45120_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Workflow execution error. __ _ WorkflowId: %1 __ _ ErrorDescription: %2

Fields #

NameDescription
workflowId GUID
errorDescription UnicodeString

Event ID 45121: ConfigurationTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Configuration
Opcode
Method

Message #

A new PowerShell endpoint was registered. __ _ EndpointName: %1 __ _ EndpointType: %2 __ _ RegisteredBy: %3

Fields #

NameDescription
endpointName UnicodeString
endpointType UnicodeString
registeredBy UnicodeString

Event ID 45122: ConfigurationTobeusedwhenoperationisjustexecutingamethod45122_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Configuration
Opcode
Method

Message #

Endpoint configuration modified. __ _ EndpointName: %1 __ _ ModifiedBy: %2

Fields #

NameDescription
endpointName UnicodeString
modifiedBy UnicodeString

Event ID 45123: ConfigurationTobeusedwhenoperationisjustexecutingamethod45123_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Configuration
Opcode
Method

Message #

Endpoint configuration unregistered. __ _ EndpointName: %1 __ _ UnregisteredBy: %2

Fields #

NameDescription
endpointName UnicodeString
unregisteredBy UnicodeString

Event ID 45124: ConfigurationTobeusedwhenoperationisjustexecutingamethod45124_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Configuration
Opcode
Method

Message #

Endpoint configuration disabled. __ _ EndpointName: %1 __ _ DisabledBy: %2

Fields #

NameDescription
endpointName UnicodeString
disabledBy UnicodeString

Event ID 45125: ConfigurationTobeusedwhenoperationisjustexecutingamethod45125_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
Configuration
Opcode
Method

Message #

Endpoint configuration enabled. __ _ EndpointName: %1 __ _ EnabledBy: %2

Fields #

NameDescription
endpointName UnicodeString
enabledBy UnicodeString

Event ID 45126: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45126_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Out of process runspace started. __ _ Command: %1

Fields #

NameDescription
command UnicodeString

Event ID 45127: WorkflowExecutionTobeusedwhenoperationisjustexecutingamethod45127_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowExecution
Opcode
Method

Message #

Parameter splatting was performed during workflow execution. __ _ Parameters: %1 __ _ Computers: %2

Fields #

NameDescription
parameters UnicodeString
computers UnicodeString

Event ID 45128: WorkflowHostingTobeusedwhenoperationisjustexecutingamethod45128_V1

#
Provider
PowerShellCore
Channel
Analytic
Task
WorkflowHosting
Opcode
Method

Message #

Workflow engine started. __ _ EndpointName: %1

Fields #

NameDescription
endpointName UnicodeString

Event ID 45129: None45129_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

Workflow manager instantiated with __ _ CheckpointPath: %1 __ _ ConfigProviderId: %2 __ _ UserName: %3 __ _ Path: %4

Fields #

NameDescription
checkpointPath UnicodeString
configProviderId UnicodeString
userName UnicodeString
path UnicodeString

Event ID 46337: None46337_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN ImportWorkflowCommand::StartWorkflowApplication. Starting invocation of workflow function. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46338: None46338_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END ImportWorkflowCommand::StartWorkflowApplication. Ending invocation of workflow function. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46339: None46339_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46340: None46340_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1

Fields #

NameDescription
TrackingId GUID

Event ID 46341: None46341_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1 : ContainerParentJob Guid %2

Fields #

NameDescription
TrackingId GUID
ContainerParentJobInstanceId GUID

Event ID 46342: None46342_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN JobLogic ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46343: None46343_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END JobLogic ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46344: None46344_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN WorkflowExecution ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46345: None46345_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END WorkflowExecution ContainerParentJob Guid %1

Fields #

NameDescription
WorkflowJobJobInstanceId GUID

Event ID 46346: None46346_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

WorkflowJob with Guid %1 added to ContainerParentJob with Guid %2

Fields #

NameDescription
WorkflowJobInstanceId GUID
ContainerParentJobInstanceId GUID

Event ID 46347: None46347_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

ProxyJob with Guid %1 associated with remote ContainerParentJob with Guid %2

Fields #

NameDescription
ProxyJobInstanceId GUID
ContainerParentJobInstanceId GUID

Event ID 46348: None46348_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN Execution of ContainerParentJob with Guid %1

Fields #

NameDescription
ContainerParentJobInstanceId GUID

Event ID 46349: None46349_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END Execution of ContainerParentJob with Guid %1

Fields #

NameDescription
ContainerParentJobInstanceId GUID

Event ID 46350: None46350_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN Execution of Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46351: None46351_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END Execution of Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46352: None46352_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN StateChanged event handler for Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46353: None46353_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END StateChanged event handler for Proxy Job with Guid %1

Fields #

NameDescription
ProxyJobInstanceId GUID

Event ID 46354: None46354_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN StateChanged event handler for Proxy Child Job with Guid %1

Fields #

NameDescription
ProxyChildJobInstanceId GUID

Event ID 46355: None46355_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END StateChanged event handler for Proxy Child Job with Guid %1

Fields #

NameDescription
ProxyChildJobInstanceId GUID

Event ID 46356: None46356_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

BEGIN Running garbage collection

Event ID 46357: None46357_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

END Running garbage collection

Event ID 46358: None46358_V1

#
Provider
PowerShellCore
Channel
Operational
Task
win:None

Message #

Persistence store has reached its maximum specified size

Event ID 49152: None49152_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

%1

Fields #

NameDescription
message UnicodeString

Event ID 49153: None49153_V1

#
Provider
PowerShellCore
Channel
Debug
Task
win:None

Message #

Trace Information: __ %1 %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 53249: PowerShellScheduledJobsTobeusedwhenoperationisjustexecutingamethod_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ScheduledJob
Opcode
Method

Message #

Scheduled Job %1 started at %2 __

Fields #

NameDescription
ScheduledJobDefName UnicodeString
StartTime UnicodeString

Event ID 53250: PowerShellScheduledJobsTobeusedwhenoperationisjustexecutingamethod53250_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ScheduledJob
Opcode
Method

Message #

Scheduled Job %1 completed at %2 with state %3 __

Fields #

NameDescription
ScheduledJobDefName UnicodeString
StopTime UnicodeString
State UnicodeString

Event ID 53251: PowerShellScheduledJobsTobeusedwhenanexceptionisraised_V1

#
Provider
PowerShellCore
Channel
Operational
Task
ScheduledJob
Opcode
Exception

Message #

Scheduled Job Exception %1: __ Message: %2 __ StackTrace: %3 __ InnerException: %4 __

Fields #

NameDescription
Name UnicodeString
Message UnicodeString
StackTrace UnicodeString
InnerException UnicodeString

Event ID 53504: PowerShellNamedPipeIPCOpen

#
Provider
PowerShellCore
Channel
Operational
Level
Informational
Task
NamedPipe
Opcode
Open

Message #

Windows PowerShell has started an IPC listening thread on process: %1 in AppDomain: %2.

Fields #

NameDescription
param1
param2

Example Event #

{
  "system": {
    "provider": "PowerShellCore",
    "guid": "F90714A8-5509-434A-BF6D-B1624C8A19A2",
    "event_source_name": "",
    "event_id": 53504,
    "version": 1,
    "level": 4,
    "task": 111,
    "opcode": 10,
    "keywords": 0,
    "time_created": "2023-11-06T01:36:40.335523+00:00",
    "event_record_id": 14,
    "correlation": {},
    "execution": {
      "process_id": 20676,
      "thread_id": 16904
    },
    "channel": "PowerShellCore/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "param1": "20676",
    "param2": "DefaultAppDomain"
  },
  "message": ""
}

References #

Event ID 53505: PowerShellNamedPipeIPCClose

#
Provider
PowerShellCore
Channel
Operational
Task
NamedPipe
Opcode
Close

Message #

Windows PowerShell has ended an IPC listening thread on process: %1 in AppDomain: %2.

Fields #

NameDescription
param1 Async)_V1(UnicodeString
param2 UnicodeString

Event ID 53506: PowerShellNamedPipeIPCTobeusedwhenanexceptionisraised_V1

#
Provider
PowerShellCore
Channel
Operational
Task
NamedPipe
Opcode
Exception

Message #

An error has occurred in Windows PowerShell IPC listening thread on process: %1 in AppDomain: %2.  Error Message: %3.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 53507: PowerShellNamedPipeIPCONNECTonnect_V1

#
Provider
PowerShellCore
Channel
Operational
Task
NamedPipe
Opcode
Connect

Message #

Windows PowerShell IPC connect on process: %1 in AppDomain: %2 for User: %3.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 53508: PowerShellNamedPipeIPCClose

#
Provider
PowerShellCore
Channel
Operational
Task
NamedPipe
Opcode
Close

Message #

Windows PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3.

Fields #

NameDescription
param1 Async)53508_V1(UnicodeString
param2 UnicodeString
param3 UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID f90714a8-5509-434a-bf6d-b1624c8a19a2

Defined in Program, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.10011.16384, captured 2026-06-02

Downloads