Windows-ApplicationModel-Store-SDK
14 events across 1 channel
Event ID 1: Message Error Code: Error Code Function: Function Source: File Name (Line Number).
#Description
Message Error Code: ErrorCode Function: Function Source: FileName (LineNumber)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
LineNumber | |
FileName | |
Function UnicodeString | |
ErrorCode |
Example Event #
{
"system": {
"provider": "Windows-ApplicationModel-Store-SDK",
"guid": "FF79A477-C45F-4A52-8AE0-2B324346D4E4",
"event_source_name": "",
"event_id": 1,
"version": 0,
"level": 2,
"task": 1,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2023-11-06T01:44:15.327827+00:00",
"event_record_id": 9073,
"correlation": {},
"execution": {
"process_id": 8956,
"thread_id": 5332
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {
"Message": "SendPageActionTelemetry: No telemetry context provider, we will use the default telemetry context",
"Line Number": 584,
"File Name": ".\\src\\Shell\\WinStore.App\\ViewModels\\PDP\\ProductActions\\ProductActionBase.cs",
"Function": "SendPageActionTelemetry",
"Error Code": -2147483648
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2: Message Exception Details: Exception Details Function: Function Source: File Name (Line Number).
#Description
Message Exception Details: Exception Details Function: Function Source: File Name (Line Number)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
Line Number | |
File Name | |
Function UnicodeString | |
Exception Details | |
LineNumber | |
FileName | |
ExceptionDetails |
Example Event #
{
"system": {
"provider": "Windows-ApplicationModel-Store-SDK",
"guid": "{FF79A477-C45F-4A52-8AE0-2B324346D4E4}",
"event_source_name": "",
"event_id": 2,
"version": 0,
"level": 2,
"task": 2,
"opcode": 0,
"keywords": -9223372036854775807,
"time_created": "2026-06-13T08:22:05.0987996+00:00",
"event_record_id": 32940,
"correlation": {},
"execution": {
"process_id": 9380,
"thread_id": 7020
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "telemetry-W11-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
}
},
"event_data": {
"Message": "Error intializing default system account. Returning NULL.",
"Line Number": "1487",
"File Name": ".\\src\\Core\\WinStore.Core\\Identity\\StoreUserProfileManager.cs",
"Function": "InitializeDefaultSystemAccount",
"Exception Details": "WinStore.Identity.AuthenticationException"
},
"message": "Error intializing default system account. Returning NULL.\r\nException Details: WinStore.Identity.AuthenticationException\r\nFunction: InitializeDefaultSystemAccount\r\nSource: .\\src\\Core\\WinStore.Core\\Identity\\StoreUserProfileManager.cs (1487)"
}
Event ID 3: Message Function: Member Name Source: File Name (Line Number).
#Description
Message Function: Member Name Source: File Name (Line Number)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
Line Number | |
File Name | |
Member Name | |
LineNumber | |
FileName | |
MemberName |
Example Event #
{
"system": {
"provider": "Windows-ApplicationModel-Store-SDK",
"guid": "{FF79A477-C45F-4A52-8AE0-2B324346D4E4}",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 3,
"task": 3,
"opcode": 0,
"keywords": -9223372036854775807,
"time_created": "2026-06-13T08:22:07.9351706+00:00",
"event_record_id": 32953,
"correlation": {},
"execution": {
"process_id": 9380,
"thread_id": 6904
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "telemetry-W11-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
}
},
"event_data": {
"Message": "Task 'WinStore.Tasks.OfferNotificationsTask+Runner' was canceled, reason: 'Terminating'.",
"Line Number": "99",
"File Name": ".\\src\\Core\\WinStore.Tasks\\Helpers\\BackgroundTaskRunner.cs",
"Member Name": "Run"
},
"message": "Task 'WinStore.Tasks.OfferNotificationsTask+Runner' was canceled, reason: 'Terminating'.\r\nFunction: Run\r\nSource: .\\src\\Core\\WinStore.Tasks\\Helpers\\BackgroundTaskRunner.cs (99)"
}
Event ID 4: Message Function: Member Name Source: File Name (Line Number).
#Description
Message Function: MemberName Source: FileName (LineNumber)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
LineNumber | |
FileName | |
MemberName |
Example Event #
{
"system": {
"provider": "Windows-ApplicationModel-Store-SDK",
"guid": "FF79A477-C45F-4A52-8AE0-2B324346D4E4",
"event_source_name": "",
"event_id": 4,
"version": 0,
"level": 4,
"task": 4,
"opcode": 0,
"keywords": 9223372036854775809,
"time_created": "2023-11-06T01:44:15.553523+00:00",
"event_record_id": 9075,
"correlation": {},
"execution": {
"process_id": 8956,
"thread_id": 5332
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {
"Message": "Launching \"SpotifyAB.SpotifyMusic_zpdnekdrzrea0!Spotify\" entry for package \"SpotifyAB.SpotifyMusic_1.222.982.0_x64__zpdnekdrzrea0\".",
"Line Number": 226,
"File Name": ".\\src\\Core\\WinStore.Core\\Acquisition\\PackageManager\\PackageManagerImplementation.cs",
"Member Name": "LaunchFirstAppListEntryAsync"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5: Message Function: MemberName Source: FileName (LineNumber).
#Event ID 2000: Process Name: ProcessName.
#Event ID 2001: Message Error: ErrorCode Function: Function Source: Source (LineNumber).
#Event ID 2002: Message Error: Error Code Function: Function Source: Source (Line Number).
#Description
Message Error: ErrorCode Function: Function Source: Source (LineNumber)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
Function AnsiString | |
ErrorCode Int32 | |
Source AnsiString | |
LineNumber UInt32 |
Example Event #
{
"system": {
"provider": "Windows-ApplicationModel-Store-SDK",
"guid": "FF79A477-C45F-4A52-8AE0-2B324346D4E4",
"event_source_name": "",
"event_id": 2002,
"version": 0,
"level": 4,
"task": 2001,
"opcode": 14,
"keywords": 9223372036854775810,
"time_created": "2026-03-11T03:43:02.825810+00:00",
"event_record_id": 30305,
"correlation": {
"ActivityID": "E83980CE-2E73-4A72-BE68-F87F00000000"
},
"execution": {
"process_id": 5560,
"thread_id": 1872
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
}
},
"event_data": {
"Message": "",
"Function": "WinStoreAuth::AuthenticationInternal::GetStorePrimaryAccountTicketForUri",
"Error Code": -2147023838,
"Source": "onecoreuap\\enduser\\winstore\\auth\\lib\\winstoreauth.cpp",
"Line Number": 364
},
"message": ""
}
Event ID 2003: Message Error: ErrorCode Function: Function Source: Source (LineNumber).
#Event ID 2004: Message Error: Error Code Function: Function Source: Source (Line Number).
#Description
Message Error: ErrorCode Function: Function Source: Source (LineNumber)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
Function AnsiString | |
ErrorCode | |
Source AnsiString | |
LineNumber |
Example Event #
{
"system": {
"provider": "Windows-ApplicationModel-Store-SDK",
"guid": "FF79A477-C45F-4A52-8AE0-2B324346D4E4",
"event_source_name": "",
"event_id": 2004,
"version": 0,
"level": 2,
"task": 2001,
"opcode": 12,
"keywords": 9223372036854775810,
"time_created": "2023-11-05T23:08:47.258586+00:00",
"event_record_id": 4804,
"correlation": {},
"execution": {
"process_id": 9824,
"thread_id": 8864
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"event_data": {
"Message": "ChkHr(HRESULT_FROM_WIN32(::RegOpenKeyExW(root, subKey, 0, ((((0x00020000L)) | (0x0001) | (0x0008) | (0x0010)) & (~(0x00100000L))), &hKey)))",
"Function": "RegistryHelper::GetStringValue",
"Error Code": -2147024894,
"Source": "onecoreuap\\enduser\\winstore\\licensing\\winrt\\lib\\registryhelper.cpp",
"Line Number": 87
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3001: Message Error: ErrorCode Function: Function Source: Source (LineNumber).
#Event ID 3002: Message Error: ErrorCode Function: Function Source: Source (LineNumber).
#Event ID 3003: Message Error: ErrorCode Function: Function Source: Source (LineNumber).
#Event ID 3004: Message Error: ErrorCode Function: Function Source: Source (LineNumber).
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID ff79a477-c45f-4a52-8ae0-2b324346d4e4
Defined in Windows.ApplicationModel.Store.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3915, captured 2026-06-02