mrxsmb.sys
Associated Error Codes
Below lists error codes and symbolic names found for this module.
| Code | Found in | Description |
|---|---|---|
| 0x30000000 | 1011 | Info |
| 0x3000000b | 1011 | Server Error |
| 0x3000000c | 1011 | Cached Error |
| 0x3000000d | 1011 | Initialize Security Context Error |
| 0x3000000e | 1011 | Security Signature Error |
| 0x300000b4 | 1011 | Start State |
| 0x300000b5 | 1011 | End State |
| 0x50000002 | 1011 | Error |
| 0x50000003 | 1011 | Warning |
| 0x50000004 | 1011 | Information |
| 0x50000005 | 1011 | Verbose |
| 0x90000001 | 1011 | Microsoft-Windows-SMBClient |
| 0x90000002 | 1011 | Microsoft-Windows-SMBClient/HelperClassDiagnostic |
| 0x90000003 | 1011 | Microsoft-Windows-SMBClient/ObjectStateDiagnostic |
| 0x90000004 | 1011 | Microsoft-Windows-SMBClient/Operational |
| 0x90000005 | 1011 | Microsoft-Windows-SMBClient/XPerfAnalytic |
| 0x90000006 | 1011 | Microsoft-Windows-SMBClient/Diagnostic |
| 0x90000007 | 1011 | Microsoft-Windows-SMBClient/Connectivity |
| 0x90000008 | 1011 | Microsoft-Windows-SMBClient/Security |
| 0x90000009 | 1011 | Microsoft-Windows-SMBClient/Audit |
| 0xb0000065 | 1011 | Create SrvCall Error: %1 Location: %2 Context: %3 |
| 0xb00000c9 | 1011 | Session Setup Error: %1 Location: %2 Context: %3 |
| 0xb000012d | 1011 | Tree Connect Error: %1 Location: %2 Context: %3 |
| 0xb0000191 | 1011 | Create VNetRoot Error: %1 Location: %2 Context: %3 |
| 0xb00001f5 | 1011 | Create File Error: %1 Location: %2 Context: %3 |
| 0xb00007d0 | 1011 | Packet Fragment (%2 bytes) |
| 0xb0004e21 | 1011 | Transitioned to State: %1 Context: %2 |
| 0xb0007597 | 1011 | SMB exchange suspended: RxContext %1 Exchange %2 ListHead %3 |
| 0xb0007598 | 1011 | SMB exchange resumed: RxContext %1 Exchange %2 ExchangeState %3 ExchangeStatus %4 |
| 0xb0007599 | 1011 | SMB buffer context suspended: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7 |
| 0xb000759a | 1011 | SMB buffer context resumed: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7 |
| 0xb000759c | 1011 | SMB Mid window blocked: Window %1 HungSession %2 |
| 0xb000759d | 1011 | SMB rechunk multi-credit request: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7 |
| 0xb000759e | 1011 | SMB initialize Mid window: Server %2 Window %3 |
| 0xb000759f | 1011 | SMB Mid window state: Window %1 CurrentWindowSize %2 CurrentWindowLimit %3 ThrottlingWindowLimit %4 OldestPendingMid %5 NextAvailableMid %6 CreditsGranted %7 |
| 0xb00075a0 | 1011 | SMB teardown Mid window: Server %2 Window %3 |
| 0xb00075a1 | 1011 | SMB copy data completion: Status %1 VcEndpoint %2 |
| 0xb00075a2 | 1011 | SMB send completion: Status %1 VcEndpoint %2 |
| 0xb00075fb | 1011 | WSK connect: SocketAddress %2 VcEndpoint %3 Socket %4 |
| 0xb00075fc | 1011 | WSK connect completion: VcEndpoint %1 Socket %2 Status %3 |
| 0xb00075fd | 1011 | WSK send: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 |
| 0xb00075fe | 1011 | WSK send completion: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 Status %5 |
| 0xb00075ff | 1011 | WSK receive: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 |
| 0xb0007600 | 1011 | WSK receive completion: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 Status %5 |
| 0xb0007601 | 1011 | Compression requested for file object %3: Status %4 |
| 0xb0007602 | 1011 | Decompression failed: VcEndpoint %1 Socket %2 ReceiveBuffer %3 ReceiveLength %4 Status %5 |
| 0xb0007603 | 1011 | Compression failed: VcEndpoint %1 Socket %2 SendBuffer %3 SendLength %4 Status %5 |
| 0xb00076c1 | 1011 | SMB session expired: SessionEntry %1 ServerName %3 |
| 0xb00076c2 | 1011 | SMB 3 part SPN reauth: SessionEntry %1 ServiceName %3 |
| 0xb00076c3 | 1011 | SMB reconnect durable open: Fcb %1 SrvOpen %2 |
| 0xb00076c4 | 1011 | SMB defer open: Fcb %1 SrvOpen %2 |
| 0xb00076c5 | 1011 | SMB undefer open: Fcb %1 SrvOpen %2 |
| 0xb00076c6 | 1011 | SMB send[%1]: [%2] (Mid/Sid/Tid) (%3/%4/%5) MidCharge %6 Creds %7 SendLengh %8 VcEndpoint %9 |
| 0xb00076c7 | 1011 | SMB receive: [%1] (Mid/Sid/Tid) (%2/%4/%5) Creds %6 Status %7 VcEndpoint %8 |
| 0xb00076c8 | 1011 | SMB receive interim: [%1] (Mid/AsyncId/Sid/Tid) (%2/%3/%4/%5) Creds %6 Status %7 VcEndpoint %8 |
| 0xb00076c9 | 1011 | SMB receive async: [%1] (AsyncId/Sid/Tid) (%3/%4/%5) Creds %6 Status %7 VcEndpoint %8 |
| 0xb00076ca | 1011 | SMB registry key: %1 = %2 |
| 0xb0007725 | 1011 | SMB update file info cache: RxContext %1 Fcb %2 FileName %4 |
| 0xb0007726 | 1011 | SMB fetch file info cache: RxContext %1 Fcb %2 FileName %4 Status %5 |
| 0xb0007727 | 1011 | SMB invalidate file info cache: RxContext %1 Fcb %2 FileName %4 |
| 0xb0007728 | 1011 | SMB update file not found cache: RxContext %1 Fcb %2 FileName %4 |
| 0xb0007729 | 1011 | SMB fetch file not found cache: RxContext %1 Fcb %2 FileName %4 Result %5 |
| 0xb000772a | 1011 | SMB invalidate file not found cache: RxContext %1 Fcb %2 FileName %4 |
| 0xb000772b | 1011 | SMB populate dir cache: RxContext %1 Fcb %2 DirName %4 |
| 0xb000772c | 1011 | SMB fetch dir cache: RxContext %1 Fcb %2 FileName %4 Status %5 |
| 0xb0007788 | 1011 | Session %1 to %6 transitioned from [%2] to [%3] with Status %4 |
| 0xb0007789 | 1011 | Share connection %1 to %6 transitioned from [%2] to [%3] with Status %4 |
| 0xb000778b | 1011 | Open handle %1 to %10%12 transitioned from [%5] to [%6] with Status %7 |
| 0xb000778c | 1011 | The local computer didn't received an SMB1 negotiate response in the last 20 minutes.n Guidance: This event indicates that no attempt was made to contact this computer via the SMB1 protocol. After %1 online days of no SMB1 contact attempts, the SMB1 Client service will automatically uninstall. |
| 0xb0007795 | 1011 | Failed to open a persistent handle. Error: %7 FileId: %2:%3 CreateGUID: %4 Path: %10%12 Reason: %8 Guidance: A persistent handle allows transparent failover on Windows File Server clusters. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information. |
| 0xb00077ed | 1011 | An invalid FSCTL_QUERY_NETWORK_INTERFACE_INFO response was sent by the server %2 |
| 0xb00077ee | 1011 | The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport. Error: %7 |
| 0xb00077ef | 1011 | The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport. Error: %7 |
| 0xb00077f0 | 1011 | The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport successfully |
| 0xb00077f1 | 1011 | The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport successfully |
| 0xb0007850 | 1011 | The server name cannot be resolved. Error: %2 Server name: %4 Guidance: The client cannot resolve the server address in DNS or WINS. This issue often manifests immediately after joining a computer to the domain, when the client's DNS registration may not yet have propagated to all DNS servers. You should also expect this event at system startup on a DNS server (such as a domain controller) that points to itself for the primary DNS. You should validate the DNS client settings on this computer using IPCONFIG /ALL and NSLOOKUP. |
| 0xb0007851 | 1011 | %1. Error: %2 Server name: %4 |
| 0xb0007853 | 10 | Failed to establish a network connection. Error: %2 Server name: %4 Server address: %6 Connection type: %7 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP, and not with SMB. A firewall that blocks TCP port 445, or TCP port 5445 when using an iWARP RDMA adapter, can also cause this issue. |
| 0xb0007854 | 10 | A network connection was disconnected. Server name: %4 Server address: %6 Connection type: %7 Guidance: This indicates that the client's connection to the server was disconnected. Frequent, unexpected disconnects when using an RDMA over Converged Ethernet (RoCE) adapter may indicate a network misconfiguration. RoCE requires Priority Flow Control (PFC) to be configured for every host, switch and router on the RoCE network. Failure to properly configure PFC will cause packet loss, frequent disconnects and poor performance. |
| 0xb0007859 | 1011 | A request timed out because there was no response from the server. Server name: %6 Session ID:%3 Tree ID:%4 Message ID:%2 Command: %1 Instance Name: %9 RetryCount: %10 ElapsedTime(ms): %11 Guidance: The server is responding over TCP but not over SMB. Ensure the Server service is running and responsive, and the disks do not have high per-IO latency, which makes the disks appear unresponsive to SMB. Also, ensure the server is responsive overall and not paused; for instance, make sure you can log on to it. |
| 0xb000785a | 1011 | Added a TCP/IP transport interface. Name: %2 InterfaceIndex: %3 Guidance: A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is re-enabled. No user action is required. |
| 0xb000785b | 1011 | Deleted a TCP/IP transport interface. Name: %2 InterfaceIndex: %3 Guidance: A TCP/IP binding was removed from the specified network adapter for the SMB client. You should expect this event when a computer shuts down or when a previously enabled network adaptor is disabled. No user action is required. |
| 0xb000785c | 1011 | Added a TDI transport interface. Name: %2 Guidance: A TDI (NetBIOS) binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this network adapter using TDI. You should expect this event when a computer restarts or when a previously disabled network adaptor is re-enabled. No user action is required. |
| 0xb000785d | 1011 | Deleted a TDI transport interface. Name: %2 Guidance: A TDI (NetBIOS) binding was removed from the specified network adapter for the SMB client. You should expect this event when a computer shuts down or when a previously enabled network adaptor is disabled. No user action is required. |
| 0xb000785e | 10 | Witness registration has completed. Status: %1 Cluster share name: %4 Cluster share type: %2 File server cluster address: %6 Guidance: The client successfully registered with the SMB Witness through RPC using TCP (port 135, then an endpoint port above 1023). No action is required. |
| 0xb000785f | 1011 | Witness deregistration has completed. Status: %1 Cluster share name: %4 Cluster share type: %2 Guidance: The client successfully de-registered with the SMB Witness through RPC using TCP (port 135, then an endpoint port above 1023). No action is required. |
| 0xb0007860 | 1011 | The server failed the negotiate request. Error: %2 Server name: %4 Guidance: The server does not support any dialect that the client is trying to negotiate, such as the client has SMB2/SMB3 disabled and the server has SMB1 disabled. |
| 0xb0007861 | 1011 | Close request failed. Error: %2 Path: %4%6 Guidance: A persistent handle (Continuous Availability) or a resilient handle failed to close. |
| 0xb0007862 | 1011 | RDMA interfaces are available but the client failed to connect to the server over RDMA transport. Server name: %2 Guidance: Both client and server have RDMA (SMB Direct) adaptors but there was a problem with the connection and the client had to fall back to using TCP/IP SMB (non-RDMA). |
| 0xb0007866 | 10 | Failed to establish an SMB multichannel network connection. Error: %2 Server name: %4 Server address: %6 Client address: %7 Instance name: %9 Connection type: %10 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP, and not with SMB. A firewall that blocks TCP port 445, or TCP port 5445 when using an iWARP RDMA adapter can also cause this issue. Since the error occurred while trying to connect extra channels, it will not result in an application error. This event is for diagnostics only. |
| 0xb000786c | 1011 | The client established its session to the server. Server name: %4 Server address: %6!S! Client address: %8!S! Session ID: %2 |
| 0xb000786d | 1011 | The client failed to establish its session to the server. Error: %1 Server name: %4 Server address: %6!S! Client address: %8!S! Session ID: %2 |
| 0xb00078ba | 1011 | A request on persistent/resilient handle failed because the handle was invalid or it exceeded the timeout. Status: %7 Type: %1 Path: %4%6 Restart count: %2 Guidance: After retrying a request on a Continuously Available (Persistent) handle or a Resilient handle, the client was unable to reconnect the handle. This event is the result of a handle recovery failure. Review other events for more details. |
| 0xb00078bb | 1011 | The SMB Multichannel registry value is not configured with default settings. Default Registry Value: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters] "DisableMultiChannel"=dword:0 Configured Registry Value: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters] "DisableMultiChannel"=dword:%2 Guidance: You can configure SMB Multichannel on the client using the Windows PowerShell cmdlet Set-SmbClientConfiguration. Disabling SMB client multichannel support is not a recommended configuration, as it can lead to degraded performance and decreased reliability if one channel or network path fails. |
| 0xb00078bc | 1011 | The SMB 3 and SMB 2 driver is not configured with the default start type. Default Start Type: DEMAND_START Configured Start Type: DISABLED Guidance: You should expect this event when disabling SMB2/SMB3 for the client using SC.EXE or editing the Windows registry. Microsoft does not recommend disabling SMB2/SMB3. Disabling SMB2/SMB3 prevents use of features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. SMB provides alternative troubleshooting workarounds to disabling SMB2/SMB3 in most cases. |
| 0xb00078bd | 1011 | The client supports SMB Direct (RDMA) and SMB Signing is in use. Share name: %2 Guidance: For optimal SMB Direct performance, you can disable SMB Signing. This configuration is less secure and you should only consider this configuration on trustworthy private networks with strict access control. |
| 0xb00078be | 1011 | The client supports SMB Direct (RDMA) and SMB Encryption is in use. Share name: %2 Guidance: For optimal SMB Direct performance, you can disable SMB Encryption on the server for shares accessed by this client. This configuration is less secure and you should only consider this configuration on trustworthy private networks with strict access control. |
| 0xb00078bf | 1011 | The Cipher Suite Order group policy setting is invalid. Guidance: This event indicates that an administrator has configured an invalid value for the "Computer Configuration\Administrative Templates\Network\Lanman Workstation\Cipher Suite Order" group policy setting. The client will use the default cipher suite order "%1" until this error is resolved. |
| 0xb00078c0 | 1011 | The RequireSecureNegotiate setting has been removed. Registry Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters Registry Value: RequireSecureNegotiate Guidance: You should expect this event when an administrator configures the RequireSecureNegotiate setting. Secure negotiate prevents man-in-the-middle attacks against SMB connection establishment. Previous versions of Windows allowed secure negotiate to be disabled. Disabling secure negotiate is no longer allowed. The client removed the setting from the registry. No user action is required. |
| 0xb0007918 | 1011 | %1. Error: %2 Security status: %3 User name: %10 Logon ID: %4 Serrver name: %6 |
| 0xb0007919 | 1011 | %1. Error: %2 Security status: %3 User name: %10 Logon ID: %4 Server name: %6 Principal name: %8 |
| 0xb000791a | 1011 | The outbound authentication failed using a network token. Error: %2 Server name: %4 Guidance: This typically indicates that delegation must be configured for a Kerberos double-hop scenario. If delegation is configured, confirm that the services are configured correctly on the middle-tier server. |
| 0xb000791b | 1011 | The LmCompatibilityLevel value is different from the default. Configured LM Compatibility Level: %2 Default LM Compatibility Level: 3 Guidance: LAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers. Value (Setting) - Description 0 (Send LM & NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 1 (Send LM & NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication. 5 (Send NTLM v2 response only/refuse LM & NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication. Incompatibly configured LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings. |
| 0xb0007922 | 1011 | The SMB client failed to connect to the share. Error: %2 Path: %4%6 |
| 0xb0007924 | 10 | The negotiate validation failed. From negotiate response: Dialect: %1 SecurityMode: %2 Capabilities: %3 ServerGuid: %4 From FSCTL_VALIDATE_NEGOTIATE_INFO response: Dialect: %5 SecurityMode: %6 Capabilities: %7 ServerGuid: %8 Guidance: The client successfully negotiated SMB dialect, security mode, capabilities and server GUID with the server, but the validation of these values then failed after connecting to a share. This may be due to a "man-in-the-middle" compromise attempt. |
| 0xb0007925 | 10 | The signing validation failed. Error:%7 Server name: %6 Session ID:%3 Tree ID:%4 Message ID:%2 Command: %1 Guidance: This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "man-in-the-middle" compromise attempt. PacketFragment:%9 |
| 0xb0007926 | 10 | The client received an unencrypted message when encryption was expected. Server name: %6 Session ID:%3 Tree ID:%4 Message ID:%2 Command: %1 Instance Name: %9 Guidance: This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "man-in-the-middle" compromise attempt. |
| 0xb0007927 | 1011 | Failed to decrypt an encrypted SMB message. Error:%7 Server name: %6 Session ID:%3 Instance Name: %9 Guidance: The client received an encrypted SMB message but cannot decrypt the data. This typically means that the communication came from a previous session that no longer exists. The encryption header may also have been damaged or tampered with on the network between the client and server. |
| 0xb0007928 | 1011 | The SMB Signing registry value is not configured with default settings. Default Registry Value: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters] "EnableSecuritySignature"=dword:1 Configured Registry Value: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters] "EnableSecuritySignature"=dword:0 Guidance: Even though you can disable, enable, or require SMB Signing, the negotiation rules changed starting with SMB2 and not all combinations operate like SMB1. The effective behavior for SMB2/SMB3 is: Client Required and Server Required = Signed Client Not Required and Server Required = Signed Server Required and Client Not Required = Signed Server Not Required and Client Not Required = Not Signed When requiring SMB Encryption, SMB Signing is not used, regardless of settings. SMB Encryption implicitly provides the same integrity guarantees as SMB Signing. |
| 0xb0007929 | 1011 | Rejected an insecure guest logon. User name: %2 Server name: %4 Guidance: This event indicates that the server attempted to log the user on as an unauthenticated guest and was denied by the client. Guest logons do not support standard security features such as signing and encryption. As a result, guest logons are vulnerable to man-in-the-middle attacks that can expose sensitive data on the network. Windows disables insecure guest logons by default. Microsoft does not recommend enabling insecure guest logons. |
| 0xb000792a | 10 | The %1 registry value is not configured with default settings. Default Registry Value: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters] "%1"=dword:0 Configured Registry Value: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters] "%1"=dword:%2 Guidance: This event indicates that an administrator has enabled insecure guest logons. An insecure guest logon occurs when a server logs the user on as an unauthenticated guest, typically in response to an authentication failure. Guest logons do not support standard security features such as signing and encryption. As a result, allowing guest logons makes the client vulnerable to man-in-the-middle attacks that can expose sensitive data on the network. Windows disables insecure guest logons by default. Microsoft does not recommend enabling insecure guest logons. |
| 0xb000792b | 1011 | Mutual authentication was unexpectedly lost after re-authenticating to %6 User %8 LogonID %4 Status %2 AuthProtocol Old %9 New %10 MutualAuthState Old %11 New %12 Clustered %13 |
| 0xb0007d00 | 1011 | SMB1 negotiate response received from remote device when SMB1 cannot be negotiated by the local computer. Dialect: %1 Server name: %3 Guidance: The client has SMB1 disabled or uninstalled. For more information: https://go.microsoft.com/fwlink/?linkid=852747. |
| 0xb0007d02 | 10 | The local computer received an SMB1 negotiate response. Dialect: %1 SecurityMode %3 Server name: %5 Guidance: SMB1 is deprecated and should not be installed nor enabled. For more information, see https://go.microsoft.com/fwlink/?linkid=852747. |
| 0xb0007d03 | 10 | The local computer didn't received an SMB1 negotiate response in the last %1 days.n Guidance: This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Client service was automatically uninstalled. |
| 0xb0009c40 | 1011 | Packet (%4 bytes) |
| 0xb0017868 | 10 | The connection was forcibly disconnected. Error: %2 Name: %4 Server address: %6 Client address: %7 Instance name: %9 Connection type: %10 Guidance: This connection is disconnected to force existing requests to fail back as soon as possible. This is a fast-fail mechanism to allow upper layers to apply their recovery policies as soon as possible. This event is for diagnostics only. |
| 0xb0017869 | 1011 | The disconnect state on connection was cleared Name: %3 Instance name: %5 Guidance: Any persistent disconnect state on this connection is cleared. Any new IO will be sent to the server as usual. This event is for diagnostics only. |
| 0xb00275fb | 1011 | %5 connect: SocketAddress %2 VcEndpoint %3 Socket %4 |
| 0xb00275fc | 1011 | %4 connect completion: VcEndpoint %1 Socket %2 Status %3 |
| 0xb00275fd | 1011 | %5 send: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 |
| 0xb00275fe | 1011 | %6 send completion: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 Status %5 |
| 0xb00275ff | 1011 | %5 receive: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 |
| 0xb0027600 | 1011 | %6 receive completion: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 Status %5 |
| 0xb0027793 | 1011 | Failed to reconnect a persistent handle. Error: %7 FileId: %2:%3 CreateGUID: %4 Path: %10%12 Reason: %8 Previous reconnect error: %13 Previous reconnect reason: %14 Guidance: A persistent handle allows transparent failover on Windows File Server clusters. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information. |
| 0xb0027794 | 1011 | Failed to reconnect a resilient handle. Error: %7 FileId: %2:%3 Path: %10%12 Reason: %8. Previous reconnect error: %13 Previous reconnect reason: %14 Guidance: A resilient handle provides guarantees to applications requesting it. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information. |
| 0xb0027853 | 10 | Failed to establish a network connection. Error: %2 Server name: %4 Server address: %6 Instance name: %9 Connection type: %10 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP, and not with SMB. A firewall that blocks TCP port 445, or TCP port 5445 when using an iWARP RDMA adapter can also cause this issue. |
| 0xb0027854 | 10 | A network connection was disconnected. Instance name: %4 Server name: %6 Server address: %8 Connection type: %9 InterfaceId: %10 Guidance: This indicates that the client's connection to the server was disconnected. Frequent, unexpected disconnects when using an RDMA over Converged Ethernet (RoCE) adapter may indicate a network misconfiguration. RoCE requires Priority Flow Control (PFC) to be configured for every host, switch and router on the RoCE network. Failure to properly configure PFC will cause packet loss, frequent disconnects and poor performance. |
| 0xb0027855 | 1011 | The client lost its session to the server. Error: %1 Server name: %5 Session ID: %2 Guidance: If the server is a Windows Failover Cluster file server, then this message occurs when the file share moves between cluster nodes. There should also be an anti-event 30806 indicating the session to the server was re-established. If the server is not a failover cluster, it is likely that the server was previously online, but it is now inaccessible over the network. |
| 0xb0027856 | 10 | The client re-established its session to the server. Server name: %5 Server address: %7 Session ID: %2 Guidance: You should expect this event if there was a previous event 30805, but the client successfully resumed the cached connection before the timeout expired. |
| 0xb0027857 | 1011 | The connection to the share was lost. Error: %1 Share name: %5 Session ID: %2 Tree ID: %3 Guidance: If the server is a Windows Failover Cluster file server, then this message occurs when the file share moves between cluster nodes. There should also be an anti-event 30808 indicating the session to the server was re-established. If the server is not a failover cluster, it is likely that the server was previously online, but it is now inaccessible over the network. |
| 0xb0027858 | 10 | The connection to the share was re-established. Share name: %5 Server address: %7 Session ID: %2 Tree ID: %3 Guidance: You should expect this event if there was a previous event 30807, but the client successfully resumed the cached connection before the timeout expired. |
| 0xb0027863 | 10 | The SMB client received a request to move to a different node on a file server cluster. File server cluster name: %4 New file server cluster address: %6 Guidance: Continuous Availability (Transparent Failover) is in use and the client computer is going to move to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required. |
| 0xb0027864 | 10 | The SMB client successfully moved to a different node on a file server cluster. File server cluster name: %4 New file server cluster address: %6 Guidance: Continuous Availability (Transparent Failover) is in use and the client computer successfully moved to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required. |
| 0xb0027865 | 1011 | The SMB client failed to move to a different node on a file server cluster. Error: %1 File server cluster name: %4 Guidance: Continuous Availability (Transparent Failover) is in use and the client computer failed to move to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). The attempt to connect to the destination server failed, which is typically due to a network configuration issue. For example, this issue may occur if the destination node's IP address cannot be resolved, if the destination node is behind a firewall, or if there is no network route from the client to the node. |
| 0xb0027867 | 10 | The connection was terminated due to one or more IO request timeouts. Error: %2 Name: %4 Server address: %6 Client address: %7 Instance name: %9 Connection type: %10 Guidance: This indicates a problem with the underlying network or the storage stack on the remote server. IO operations were not completed within the allotted time. The application may not see this failure because IOs are usually retried on a different connection. This event is for diagnostics only. |
| 0xb00278b4 | 1011 | The handle was created without persistence. File ID: %2:%3 CreateGUID: %4 Path: %10%12 Guidance: The server supports Continuous Availability (persistent handles) and the request to create the handle succeeded. However, the server did not grant persistence. You should verify that the Resume Key Filter is running on the server and is attached to the target volume. |
| 0xb00278b8 | 1011 | The server does not support multichannel. Server name: %2 Guidance: The client attempted to use SMB Multichannel, but an administrator has disabled multichannel support on the server. This may also be a non-Microsoft file server that does not support multichannel or has multichannel disabled. You can enable SMB Multichannel on the server using this Windows PowerShell cmdlet: Set-SmbServerConfiguration -EnableMultiChannel:$true. This event does not apply to the multichannel settings of SMB client, which are controlled by the Set-SmbClientConfiguration Windows PowerShell cmdlet. Enabling or disabling client multichannel support does not affect server multichannel support. |
| 0xb00278b9 | 1011 | The client cannot connect to the server due to a multichannel constraint registry setting. Server name: %2 Guidance: The client attempted to use SMB Multichannel, but an administrator has configured multichannel support to prevent multichannel on the client. You can configure SMB Multichannel on the client using the Windows PowerShell cmdlets: New-SmbMultichannelConstraint and Remove-SmbMultichannelConstraint. |
| 0xd0000001 | 1011 | Active |
| 0xd0000002 | 1011 | Disconnected |
| 0xd0000003 | 1011 | Suspended |
| 0xd0000004 | 1011 | Construction in progress |
| 0xd0000005 | 1011 | Recovery in progress |
| 0xd0000006 | 1011 | Disconnect in progress |
| 0xd0000007 | 1011 | Invalidation in progress |
| 0xd0000008 | 1011 | Invalid |
| 0xd0000009 | 1011 | Deleted |
| 0xd000000a | 10 | Tdi |
| 0xd000000b | 10 | Wsk |
| 0xd000000c | 1011 | Rdma |
| 0xd000000d | 1011 | VMBUS |
| 0xd000000e | 1011 | Quic |
| 0xd000000f | 1011 | Smb2DiagReasonNotSpecified |
| 0xd0000010 | 1011 | Smb2DiagReasonDns |
| 0xd0000011 | 1011 | Smb2DiagReasonSetSocketSecurity |
| 0xd0000012 | 1011 | Smb2DiagReasonIPSec |
| 0xd0000013 | 1011 | Smb2DiagReasonNetworkConnect |
| 0xd0000014 | 1011 | Smb2DiagReasonNegotiateValidation |
| 0xd0000015 | 1011 | Smb2DiagReasonExchangeExpiry |
| 0xd0000016 | 1011 | Smb2DiagReasonDisconnectIndication |
| 0xd0000017 | 1011 | Smb2DiagReasonNegativeCache |
| 0xd0000018 | 1011 | Smb2DiagReasonConsecutiveSessionSetupFailures |
| 0xd0000019 | 1011 | Smb2DiagReasonQuicServerCertificateError |
| 0xd000001a | 1011 | Smb2DiagReasonQuicServerConfigFailure |
| 0xd000001b | 10 | Smb2DiagReasonAcquireCredHandle |
| 0xd000001c | 10 | Smb2DiagReasonISC |
| 0xd000001d | 10 | Smb2DiagReasonSessionSetupResponse |
| 0xd000001e | 10 | Smb2DiagReasonMADowngrade |
| 0xd000001f | 10 | Smb2DiagReasonCreateSigningKey |
| 0xd0000020 | 10 | Smb2DiagReasonRegisterCryptoKeys |
| 0xd0000021 | 10 | Smb2DiagReasonQCA |
| 0xd0000022 | 10 | Smb2DiagReasonEncryptionOnNullSession |
| 0xd0000023 | 10 | Smb2DiagReasonTreeConnectResponse |
| 0xd0000024 | 10 | Smb2DiagReasonValidateNegotiateFsctl |
| 0xd0000025 | 10 | Smb2DiagReasonHandleReconnect |
| 0xd0000026 | 10 | Smb2DiagReasonCreateResponse |
| 0xd0000027 | 10 | Smb2DiagReasonExchangeCancellation |
| 0xd0000028 | 10 | Smb2DiagReasonExchangeNoBindingObject |
| 0xd0000029 | 10 | Smb2DiagReasonExchangeSendFailure |
| 0xd000002a | 10 | Smb2DiagReasonObjectSuspended |
| 0xd000002b | 10 | Smb2DiagReasonUserDisconnect |
| 0xd000002c | 10 | Smb2DiagReasonHandleClosed |
| 0xd000002d | 10 | Smb2DiagDisconnectReasonReceiveContextAllocation |
| 0xd000002e | 10 | Smb2DiagDisconnectReasonPaddingAllocation |
| 0xd000002f | 10 | Smb2DiagDisconnectReasonExchangeReceiveHandlerError |
| 0xd0000030 | 10 | Smb2DiagDisconnectReasonMessageBufferAllocation |
| 0xd0000031 | 10 | Smb2DiagDisconnectReasonVcEndpointTornDown |
| 0xd0000032 | 10 | Smb2DiagDisconnectReasonMessageSizeReceiveError |
| 0xd0000033 | 10 | Smb2DiagDisconnectReasonMessageSizeTooLargeError |
| 0xd0000034 | 10 | Smb2DiagDisconnectReasonMessageCopyError |
| 0xd0000035 | 10 | Smb2DiagDisconnectReasonVcReceiveHandlerError |
| 0xd0000036 | 10 | Smb2DiagDisconnectReasonVcReceiveError |
| 0xd0000037 | 10 | Negotiate |
| 0xd0000038 | 10 | Session setup |
| 0xd0000039 | 10 | Logoff |
| 0xd000003a | 10 | Tree connect |
| 0xd000003b | 10 | Tree disconnect |
| 0xd000003c | 10 | Create |
| 0xd000003d | 10 | Close |
| 0xd000003e | 10 | Flush |
| 0xd000003f | 10 | Read |
| 0xd0000040 | 10 | Write |
| 0xd0000041 | 10 | Lock |
| 0xd0000042 | 10 | Ioctl |
| 0xd0000043 | 10 | Cancel |
| 0xd0000044 | 10 | Echo |
| 0xd0000045 | 10 | Query directory |
| 0xd0000046 | 10 | Change notify |
| 0xd0000047 | 10 | Query info |
| 0xd0000048 | 10 | Set info |
| 0xd0000049 | 10 | Oplock break |
| 0xd000004a | 10 | Create |
| 0xd000004b | 10 | Close |
| 0xd000004c | 10 | Read |
| 0xd000004d | 10 | Write |
| 0xd000004e | 10 | Query information |
| 0xd000004f | 10 | Set information |
| 0xd0000050 | 10 | Query EA |
| 0xd0000051 | 10 | Set EA |
| 0xd0000052 | 10 | Flush buffers |
| 0xd0000053 | 10 | Query volume information |
| 0xd0000054 | 10 | Set volume information |
| 0xd0000055 | 10 | Directory control |
| 0xd0000056 | 10 | File system control |
| 0xd0000057 | 10 | Device control |
| 0xd0000058 | 10 | Internal device control |
| 0xd0000059 | 10 | Lock control |
| 0xd000005a | 10 | Cleanup |
| 0xd000005b | 10 | Query security |
| 0xd000005c | 10 | Set security |
| 0xd000005d | 10 | Query quota information |
| 0xd000005e | 10 | Set quota information |
| 0xd000005f | 10 | Internal probe I/O |
| 0xd0000060 | 10 | Symmetric |
| 0xd0000061 | 10 | Asymmetric |
| 0x10000001 | 11 | Perf |
| 0x10000002 | 11 | NetworkingPerf |
| 0x10000003 | 11 | Info |
| 0x10000004 | 11 | InfoCacheInfo |
| 0x10000005 | 11 | TFO |
| 0x10000006 | 11 | Multichannel |
| 0x10000007 | 11 | Connectivity |
| 0x10000008 | 11 | Authentication |
| 0x10000009 | 11 | Authorization |
| 0x1000000a | 11 | Security |
| 0x1000000b | 11 | IOPerf |
| 0x1000000c | 11 | PerfSummary |
| 0x1000000d | 11 | PerfRundown |
| 0x1000000e | 11 | IOPerfOptional |
| 0x10000011 | 11 | ConnectivityNoisy |
| 0x1000001f | 11 | PacketStart |
| 0x10000020 | 11 | PacketEnd |
| 0x10000021 | 11 | SendPath |
| 0x10000022 | 11 | ReceivePath |
| 0x1000002b | 11 | Packet |
| 0x1000002f | 11 | Diagnostic |
| 0x10000030 | 11 | PduFull |
| 0x30000001 | 11 | Start |
| 0x70000001 | 11 | Smb2PerfRxContextStart |
| 0x70000002 | 11 | Smb2PerfExchangeStart |
| 0x70000003 | 11 | Smb2PerfBufferContextStart |
| 0x70000004 | 11 | Smb2PerfRxContextStop |
| 0x70000005 | 11 | Smb2PerfExchangeStop |
| 0x70000006 | 11 | Smb2PerfBufferContextStop |
| 0x70000007 | 11 | Smb2PerfWorkTransition |
| 0x70000008 | 11 | Smb2PerfRxContextReadSummary |
| 0x70000009 | 11 | Smb2PerfRxContextWriteSummary |
| 0x7000000a | 11 | Smb2PerfRxContextCreateSummary |
| 0x7000000b | 11 | Smb2PerfRxContextCloseSummary |
| 0x7000000c | 11 | Smb2PerfRxContextQueryDirectorySummary |
| 0x7000000d | 11 | Smb2PerfRxContextFsctlSummary |
| 0x7000000e | 11 | Smb2PerfExchangeReadSummary |
| 0x7000000f | 11 | Smb2PerfExchangeWriteSummary |
| 0x70000010 | 11 | Smb2PerfExchangeCreateSummary |
| 0x70000011 | 11 | Smb2PerfExchangeCloseSummary |
| 0x70000012 | 11 | Smb2PerfExchangeQueryDirectorySummary |
| 0x70000013 | 11 | Smb2PerfExchangeFsctlSummary |
| 0x70000014 | 11 | Smb2PerfBufferContextReadSummary |
| 0x70000015 | 11 | Smb2PerfBufferContextWriteSummary |
| 0x70000016 | 11 | Smb2PerfBufferContextCreateSummary |
| 0x70000017 | 11 | Smb2PerfBufferContextCloseSummary |
| 0x70000018 | 11 | Smb2PerfBufferContextQueryDirectorySummary |
| 0x70000019 | 11 | Smb2PerfBufferContextFsctlSummary |
| 0x7000001a | 11 | Smb2PerfFCBCaptureSummary |
| 0x7000001b | 11 | CreateSrvCallError |
| 0x7000001c | 11 | SessionSetupError |
| 0x7000001d | 11 | CreateVNetRootError |
| 0x7000001e | 11 | CreateFileError |
| 0x7000001f | 11 | CreateFile |
| 0x70000020 | 11 | SmbSuspendExchange |
| 0x70000021 | 11 | SmbResumeExchange |
| 0x70000022 | 11 | SmbResumeBufferCtxt |
| 0x70000023 | 11 | SmbMidWindowBlocked |
| 0x70000024 | 11 | SmbRechunkRequest |
| 0x70000025 | 11 | SmbInitializeMidWindow |
| 0x70000026 | 11 | SmbMidWindowState |
| 0x70000027 | 11 | SmbTeardownMidWindow |
| 0x70000028 | 11 | SmbDataReady |
| 0x70000029 | 11 | SmbSendCompletion |
| 0x7000002a | 11 | NetConnect |
| 0x7000002b | 11 | NetConnectCompletion |
| 0x7000002c | 11 | NetSend |
| 0x7000002d | 11 | NetSendCompletion |
| 0x7000002e | 11 | NetReceive |
| 0x7000002f | 11 | NetReceiveCompletion |
| 0x70000030 | 11 | CompressionRequested |
| 0x70000031 | 11 | DecompressionFailure |
| 0x70000032 | 11 | CompressionFailure |
| 0x70000033 | 11 | SmbSessionExpired |
| 0x70000034 | 11 | Smb3PartSPNReauth |
| 0x70000035 | 11 | SmbReconnect |
| 0x70000036 | 11 | SmbDeferOpen |
| 0x70000037 | 11 | SmbUndeferOpen |
| 0x70000038 | 11 | SmbSend |
| 0x70000039 | 11 | SmbReceive |
| 0x7000003a | 11 | SmbReceiveInterim |
| 0x7000003b | 11 | SmbReceiveAsync |
| 0x7000003c | 11 | SmbRegistryKey |
| 0x7000003d | 11 | SmbUpdateInfoCache |
| 0x7000003e | 11 | SmbFetchInfoCache |
| 0x7000003f | 11 | SmbInvalidateInfoCache |
| 0x70000040 | 11 | SmbUpdateFNFCache |
| 0x70000041 | 11 | SmbFetchFNFCache |
| 0x70000042 | 11 | SmbInvalidateFNFCache |
| 0x70000043 | 11 | SmbPopulateDirCache |
| 0x70000044 | 11 | SmbFetchDirCache |
| 0x70000045 | 11 | SessionStateTransition |
| 0x70000046 | 11 | VNetRootStateTransition |
| 0x70000047 | 11 | OpenHandleStateTransition |
| 0x70000048 | 11 | NoSMB1ObservedInLastPeriod |
| 0x70000049 | 11 | PersistentHandleFailure |
| 0x7000004a | 11 | ResilientHandleFailure |
| 0x7000004b | 11 | HandleOpenFailure |
| 0x7000004c | 11 | ServerNetworkInterfaceInvalid |
| 0x7000004d | 11 | WskConnectFailure |
| 0x7000004e | 11 | RdmaConnectFailure |
| 0x7000004f | 11 | WskConnectSuccess |
| 0x70000050 | 11 | RdmaConnectSuccess |
| 0x70000051 | 11 | WskGetAddressInfoFailure |
| 0x70000052 | 11 | SetSocketSecurityFailure |
| 0x70000053 | 11 | IPSecFailure |
| 0x70000054 | 11 | NetworkConnectFailure |
| 0x70000055 | 11 | DisconnectIndication |
| 0x70000056 | 11 | SessionFailure |
| 0x70000057 | 11 | SessionEstablished |
| 0x70000058 | 11 | ShareConnectionFailure |
| 0x70000059 | 11 | ShareConnectionEstablished |
| 0x7000005a | 11 | ExpiredExchange |
| 0x7000005b | 11 | TcpIpTransportArrival |
| 0x7000005c | 11 | TcpIpTransportRemoval |
| 0x7000005d | 11 | TdiTransportArrival |
| 0x7000005e | 11 | TdiTransportRemoval |
| 0x7000005f | 11 | WitnessRegistration |
| 0x70000060 | 11 | WitnessDeregistration |
| 0x70000061 | 11 | NegotiateFailure |
| 0x70000062 | 11 | CloseFailure |
| 0x70000063 | 11 | RdmaFallback |
| 0x70000064 | 11 | WitnessMove |
| 0x70000065 | 11 | WitnessMoveSuccess |
| 0x70000066 | 11 | WitnessMoveFailure |
| 0x70000067 | 11 | MultiChannelNetworkConnectFailure |
| 0x70000068 | 11 | HungConnectionFailure |
| 0x70000069 | 11 | ConnectionForceDisconnected |
| 0x7000006a | 11 | ConnectionDisconnectStateCleared |
| 0x7000006b | 11 | NegotiateResponseEncryptionCapabilitiesFailure |
| 0x7000006c | 11 | CertificateMappingNotFound |
| 0x7000006d | 11 | SessionEstablishedNoisy |
| 0x7000006e | 11 | SessionSetupErrorNoisy |
| 0x7000006f | 11 | SmbConnectionInitiatedSelectedInfo |
| 0x70000070 | 11 | HandlePersistenceNotGranted |
| 0x70000071 | 11 | ServerMultiChannelIncapable |
| 0x70000072 | 11 | ServerMultiChannelConstraint |
| 0x70000073 | 11 | RequestRetryFailure |
| 0x70000074 | 11 | MultiChannelDisabled |
| 0x70000075 | 11 | Smb2Disabled |
| 0x70000076 | 11 | RdmaWithSigning |
| 0x70000077 | 11 | RdmaWithEncryption |
| 0x70000078 | 11 | InvalidCipherSuiteOrder |
| 0x70000079 | 11 | RequireSecureNegotiateIsDeprecated |
| 0x7000007a | 11 | IsolatedTransportServerEntryInfo |
| 0x7000007b | 11 | SmbRdmaRundownActive |
| 0x7000007c | 11 | SmbRdmaRundownComplete |
| 0x7000007d | 11 | SmbRdmaReactivation |
| 0x7000007e | 11 | SmbRdmaReactivationComplete |
| 0x7000007f | 11 | SmbRdmaSMBDirectLoad |
| 0x70000080 | 11 | SmbComponentCapabilities |
| 0x70000081 | 11 | SmbInvalidPortSpecified |
| 0x70000082 | 11 | SmbConnectionInitiatedNotSelectedInfo |
| 0x70000083 | 11 | SmbDialectChange |
| 0x70000084 | 11 | AcquireCredHandleFailure |
| 0x70000085 | 11 | ISCFailure |
| 0x70000086 | 11 | NetworkTokenFailure |
| 0x70000087 | 11 | LMCompatibilityLevel |
| 0x70000088 | 11 | TreeConnectFailure |
| 0x70000089 | 11 | NegotiateValidationFailure |
| 0x7000008a | 11 | SigningFailure |
| 0x7000008b | 11 | EncryptionFailure |
| 0x7000008c | 11 | DecryptionFailure |
| 0x7000008d | 11 | EnableSecuritySignatureNonDefault |
| 0x7000008e | 11 | RejectedInsecureGuestAuth |
| 0x7000008f | 11 | InsecureGuestAuthEnabled |
| 0x70000090 | 11 | MADowngradeDetected |
| 0x70000091 | 11 | SessionKeyTooShort |
| 0x70000092 | 11 | DirectDataPlacementSecurity |
| 0x70000093 | 11 | UnexpectedSMB1ResponseReceived |
| 0x70000094 | 11 | SMB1ResponseReceived |
| 0x70000095 | 11 | UninstallSMB1Client |
| 0x70000096 | 11 | PacketFragment |
| 0x70000097 | 11 | Packet |
| 0x70000098 | 11 | TreeConnectError |
| 0x70000099 | 11 | SmbSuspendBufferCtxt |
| 0x7000009a | 11 | SmbLsassCallDurationInfo |
| 0x7000009b | 11 | SmbLsassCallDurationWarning |
| 0x7000009c | 11 | AllowedInsecureGuestAuth |
| 0x7000009d | 11 | ServerDoesNotSupportSigning |
| 0x7000009e | 11 | ServerDoesNotSupportEncryption |
| 0x7000009f | 11 | InsecureGuestLogon |
| 0x700000a0 | 11 | MutualAuthServerDeniedAccess |
| 0x700000a1 | 11 | ConnectionEstablished |
| 0x700000a2 | 11 | NTLMBlocked |
| 0x700000a3 | 11 | ShareInitialConnectionEstablished |
| 0x700000a4 | 11 | ServerCertificateRevocationChecksFailed |
| 0x700000a5 | 11 | ServerAuthenticationFailure |
| 0x700000a7 | 11 | RequestedTransportDisabled |
| 0xb0007853 | 11 | Failed to establish a network connection. Error: %2 Server name: %4 Server address: %6!S! Connection type: %7 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP, and not with SMB. A firewall that blocks TCP port 445, or TCP port 5445 when using an iWARP RDMA adapter, can also cause this issue. |
| 0xb0007854 | 11 | A network connection was disconnected. Server name: %4 Server address: %6!S! Connection type: %7 Guidance: This indicates that the client's connection to the server was disconnected. Frequent, unexpected disconnects when using an RDMA over Converged Ethernet (RoCE) adapter may indicate a network misconfiguration. RoCE requires Priority Flow Control (PFC) to be configured for every host, switch and router on the RoCE network. Failure to properly configure PFC will cause packet loss, frequent disconnects and poor performance. |
| 0xb000785e | 11 | Witness registration has completed. Status: %1 Cluster share name: %4 Cluster share type: %2 File server cluster address: %6!S! Guidance: The client successfully registered with the SMB Witness through RPC using TCP (port 135, then an endpoint port above 1023). No action is required. |
| 0xb0007866 | 11 | Failed to establish an SMB multichannel network connection. Error: %2 Server name: %4 Server address: %6!S! Client address: %7!S! Instance name: %9 Connection type: %10 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP or QUIC/UDP, and not with SMB. A firewall that blocks TCP port 445 or UDP port 443 or TCP port 5445 when using an iWARP RDMA adapter can also cause this issue. Since the error occurred while trying to connect extra channels, it will not result in an application error. This event is for diagnostics only. |
| 0xb000786a | 11 | The SMB negotiate response processing failed on the client to determine the selected encryption cipher for the client and server. Please ensure there is a common cipher between the client and server. Client encryption cipher suite order (most to least preferred): %2 Server replied back with its selected encryption cipher ID: %4 |
| 0xb000786b | 11 | Could not find a certificate mapping that matches the server name. Connection type: %1 Server name: %3. |
| 0xb000786e | 11 | The SMB redirector selected the connection initiated with the following parameters: Server name: %2 Server socket address: %5 Client socket address: %7 Client certificate thumbprint: %12 Transport: %3 Instance Name: %9 |
| 0xb000786f | 11 | The SMB client was denied access to the SMB server during mutual authentication. Server name: %2 Server socket address: %5 Client socket address: %7 Client certificate thumbprint: %11 Transport: %3 Instance Name: %9 |
| 0xb0007870 | 11 | The SMB connection was successfully established. Server name: %2 Server socket address: %5 Client socket address: %7 Connection ID: %12 Client certificate thumbprint: %14 Transport: %3 Instance Name: %9 Port Origin: %10 Guidance: The event occurs when server authentication succeeds. The connection may later be closed if client authentication fails or if the client is denied access to the server. |
| 0xb0007871 | 11 | The initial connection to the share was established. Share name: %5 Server address: %7!S! Session ID: %2 Tree ID: %3 Transport type: %8 Signing used: %9 Encryption used: %10 Compression requested: %11 NTLM blocked: %12 |
| 0xb0007872 | 11 | The client was unable to perform revocation checks on the server certificate chain. The connection will proceed. Verification Status: %1 Server name: %3 Server socket address: %6 Client socket address: %8 Connection ID: %13 Client certificate thumbprint: %15 Transport: %4 Instance Name: %10 Port Origin: %11 |
| 0xb0007873 | 11 | Server authentication failed. Error: %1 Server name: %3 Server socket address: %6 Client socket address: %8 Connection ID: %13 Client certificate thumbprint: %15 Transport: %4 Instance Name: %10 Port Origin: %11 |
| 0xb0007875 | 11 | The requested transport is disabled. Server name: %2 Server socket address: %5 Transport: %3 |
| 0xb00078c1 | 11 | Server %2 share %4 has requested client to use isolated connections to connection to the share. Asymmetric flag %5. Isolated transport flag %6. NetRoot already use isolated connections %7. |
| 0xb00078c2 | 11 | RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently %1 active RDMA resources. |
| 0xb00078c3 | 11 | RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: %1. |
| 0xb00078c4 | 11 | Reactivation of RDMA support has commenced. |
| 0xb00078c5 | 11 | RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: %1. |
| 0xb00078c6 | 11 | SMBDirect load attempt complete. Success: %1 Status code: %2 Service path: %4 |
| 0xb00078e6 | 11 | Component capabilities: %1 Internal patch number: %2 |
| 0xb00078e7 | 11 | The alternative port %1 is not a valid port within the range 0 to 65535 for mapping name %3:%5. |
| 0xb00078e8 | 11 | The SMB redirector did not select the connection initiated with the following parameters: Server name: %2 IP Address: %5 Transport: %3 Instance Name:%7 Port Origin: %8 The failure status associated with this decision: %9 |
| 0xb00078e9 | 11 | SMB Dialect Change %1 was changed from %2 to %3. |
| 0xb00078ea | 11 | It took %2 secs to execute %1. |
| 0xb00078eb | 11 | It took %2 secs to execute %1 which is longer than threshold of %3 secs. This warning is because %1 is taking longer than expected. |
| 0xb0007924 | 11 | The negotiate validation failed. From negotiate response: Dialect: %1 SecurityMode: %2 Capabilities: %3 ServerGuid: %4 From FSCTL_VALIDATE_NEGOTIATE_INFO response: Dialect: %5 SecurityMode: %6 Capabilities: %7 ServerGuid: %8 Guidance: The client successfully negotiated SMB dialect, security mode, capabilities and server GUID with the server, but the validation of these values then failed after connecting to a share. This may be due to a "adversary-in-the-middle" compromise attempt. |
| 0xb0007925 | 11 | The signing validation failed. Error:%7 Server name: %6 Session ID:%3 Tree ID:%4 Message ID:%2 Command: %1 Guidance: This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "adversary-in-the-middle" compromise attempt. PacketFragment:%9 |
| 0xb0007926 | 11 | The client received an unencrypted message when encryption was expected. Server name: %6 Session ID:%3 Tree ID:%4 Message ID:%2 Command: %1 Instance Name: %9 Guidance: This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "adversary-in-the-middle" compromise attempt. |
| 0xb000792a | 11 | Guidance: An administrator has enabled AllowInsecureGuestAuth. Clients using insecure guest logons are more vulnerable to attackers-in-the-middle, phishing, and malware. |
| 0xb000792c | 11 | Session key for connection is weaker than required. Connection will be closed as a result. Server: %2 User: %6 Session key length: %3 Required Session key length: %4 Guidance: To establish a connection with a shorter session key, set the following registry DWORD value name with the value as decimal bits: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters] "MinimumSessionKeyLength" Important: If you have configured the 'Network security: Configure encryption types allowed for Kerberos' security policy to prevent use of 256-bit keys but also set the MinimumSessionKeyLength greater than 128 bits, the computer will not be able to make SMB connections. Setting MinimumSessionKeyLength higher than 128 bits will also prevent SMB connections using NTLM. |
| 0xb000792d | 11 | SMB DDP security changed from %1 to %2. |
| 0xb000792e | 11 | Allowed an insecure guest logon. User name: %2 Server name: %4 Guidance: This event indicates that the server attempted to log the user on as an unauthenticated guest and was allowed by the client. |
| 0xb000792f | 11 | NTLM is prohibited for authentication on the server Server name: %2 NTLM was disabled by user or by administrator using policies. For more information: https://go.microsoft.com/fwlink/?linkid=2267451. |
| 0xb0007cfd | 11 | The SMB client was logged on as Guest account. Server name: %2 |
| 0xb0007cfe | 11 | The SMB client observed that the server doesn't support signing. Server name: %2 Client requires signing: %3 |
| 0xb0007cff | 11 | The SMB client observed that the server doesn't support encryption. Server name: %2 Client requires encyption: %3 |
| 0xb0007d02 | 11 | The local computer received an SMB1 negotiate response. Dialect: %2 SecurityMode %3 Server name: %5 Guidance: SMB1 is deprecated and should not be installed nor enabled. For more information, see https://go.microsoft.com/fwlink/?linkid=852747. |
| 0xb0007d03 | 11 | The local computer didn't received an SMB1 negotiate response in the last %1 days.n Guidance: This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Client service was automatically uninstalled. The computer must be restarted for SMB1 removal to take effect. |
| 0xb0007d04 | 11 | SMB2 rxcontext performance work started |
| 0xb0007d05 | 11 | SMB2 exchange performance work started |
| 0xb0007d06 | 11 | SMB2 buffer context performance work started |
| 0xb0007d07 | 11 | SMB2 performance work transition |
| 0xb0007d08 | 11 | SMB2 rxcontext performance work read summary |
| 0xb0007d09 | 11 | SMB2 rxcontext performance work write summary |
| 0xb0007d0a | 11 | SMB2 rxcontext performance work create summary |
| 0xb0007d0b | 11 | SMB2 rxcontext performance work close summary |
| 0xb0007d0c | 11 | SMB2 rxcontext performance work query directory summary |
| 0xb0007d0d | 11 | SMB2 rxcontext performance work fsctl summary |
| 0xb0007d1c | 11 | SMB2 exchange performance work read summary |
| 0xb0007d1d | 11 | SMB2 exchange performance work write summary |
| 0xb0007d1e | 11 | SMB2 exchange performance work create summary |
| 0xb0007d1f | 11 | SMB2 exchange performance work close summary |
| 0xb0007d20 | 11 | SMB2 exchange performance work query directory summary |
| 0xb0007d21 | 11 | SMB2 exchange performance work fsctl summary |
| 0xb0007d30 | 11 | SMB2 buffer context performance work read summary |
| 0xb0007d31 | 11 | SMB2 buffer context performance work write summary |
| 0xb0007d32 | 11 | SMB2 buffer context performance work create summary |
| 0xb0007d33 | 11 | SMB2 buffer context performance work close summary |
| 0xb0007d34 | 11 | SMB2 buffer context performance work query directory summary |
| 0xb0007d35 | 11 | SMB2 buffer context performance work fsctl summary |
| 0xb0007d44 | 11 | SMB2 FCB capture summary |
| 0xb0017868 | 11 | The connection was forcibly disconnected. Error: %2 Name: %4 Server address: %6!S! Client address: %7!S! Instance name: %9 Connection type: %10 Guidance: This connection is disconnected to force existing requests to fail back as soon as possible. This is a fast-fail mechanism to allow upper layers to apply their recovery policies as soon as possible. This event is for diagnostics only. |
| 0xb0017872 | 11 | The client was unable to perform revocation checks on the server certificate chain. The connection will proceed. Verification Status: %1 Server name: %3 Server socket address: %6 Client socket address: %8 Client certificate thumbprint: %12 Transport: %4 Instance Name: %10 |
| 0xb0017873 | 11 | Server authentication failed. Error: %1 Server name: %3 Server socket address: %6 Client socket address: %8 Client certificate thumbprint: %12 Transport: %4 Instance Name: %10 |
| 0xb00178c6 | 11 | SMBDirect load attempt complete. Success: %1 Status code: %2 Service path: %4 Device name: %6 |
| 0xb0027853 | 11 | Failed to establish a network connection. Error: %2 Server name: %4 Server address: %6!S! Instance name: %9 Connection type: %10 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP or QUIC/UDP, and not with SMB. A firewall that blocks TCP port 445 or UDP port 443 or TCP port 5445 when using an iWARP RDMA adapter can also cause this issue. |
| 0xb0027854 | 11 | A network connection was disconnected. Instance name: %4 Server name: %6 Server address: %8!S! Connection type: %9 InterfaceId: %10 Guidance: This indicates that the client's connection to the server was disconnected. Frequent, unexpected disconnects when using an RDMA over Converged Ethernet (RoCE) adapter may indicate a network misconfiguration. RoCE requires Priority Flow Control (PFC) to be configured for every host, switch and router on the RoCE network. Failure to properly configure PFC will cause packet loss, frequent disconnects and poor performance. |
| 0xb0027856 | 11 | The client re-established its session to the server. Server name: %5 Server address: %7!S! Session ID: %2 Guidance: You should expect this event if there was a previous event 30805, but the client successfully resumed the cached connection before the timeout expired. |
| 0xb0027858 | 11 | The connection to the share was re-established. Share name: %5 Server address: %7!S! Session ID: %2 Tree ID: %3 Guidance: You should expect this event if there was a previous event 30807, but the client successfully resumed the cached connection before the timeout expired. |
| 0xb0027863 | 11 | The SMB client received a request to move to a different node on a file server cluster. File server cluster name: %4 New file server cluster address: %6!S! Guidance: Continuous Availability (Transparent Failover) is in use and the client computer is going to move to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required. |
| 0xb0027864 | 11 | The SMB client successfully moved to a different node on a file server cluster. File server cluster name: %4 New file server cluster address: %6!S! Guidance: Continuous Availability (Transparent Failover) is in use and the client computer successfully moved to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required. |
| 0xb0027866 | 11 | Failed to establish an SMB multichannel network connection. Error: %2 Server name: %4 Server address: %6!S! Client address: %7!S! Instance name: %9 Connection type: %10 Port origin:%11 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP or QUIC/UDP, and not with SMB. A firewall that blocks the TCP or UDP port listed in the Server Address field can also cause this issue. Since the error occurred while trying to connect extra channels, it will not result in an application error. This event is for diagnostics only. |
| 0xb0027867 | 11 | The connection was terminated due to one or more IO request timeouts. Error: %2 Name: %4 Server address: %6!S! Client address: %7!S! Instance name: %9 Connection type: %10 Guidance: This indicates a problem with the underlying network or the storage stack on the remote server. IO operations were not completed within the allotted time. The application may not see this failure because IOs are usually retried on a different connection. This event is for diagnostics only. |
| 0xb002786e | 11 | The SMB redirector selected the connection initiated with the following parameters: Server name: %2 Server socket address: %5 Client socket address: %7 Connection ID: %13 Client certificate thumbprint: %15 Transport: %3 Instance Name: %9 Port Origin: %10 |
| 0xb002786f | 11 | The SMB client was denied access to the SMB server during mutual authentication. Server name: %2 Server socket address: %5 Client socket address: %7 Connection ID: %12 Client certificate thumbprint: %14 Transport: %3 Instance Name: %9 Port Origin: %10 |
| 0xb0027925 | 11 | The signing validation failed. Error:%7 Server name: %6 Session ID:%3 Tree ID:%4 Message ID:%2 Command: %1 Server address: %13!S! Client address: %15!S! Guidance: This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "adversary-in-the-middle" compromise attempt. PacketFragment:%9 |
| 0xb0027926 | 11 | The client received an unencrypted message when encryption was expected. Server name: %6 Session ID:%3 Tree ID:%4 Message ID:%2 Command: %1 Instance Name: %9 Server address: %13!S! Client address: %15!S! Guidance: This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "adversary-in-the-middle" compromise attempt. |
| 0xb0037853 | 11 | Failed to establish a network connection. Error: %2 Server name: %4 Server address: %6!S! Instance name: %9 Connection type: %10 Port origin: %11 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP or QUIC/UDP, and not with SMB. A firewall that blocks the TCP or UDP port listed in the Server Address field can also cause this issue. |
| 0xb0037856 | 11 | The client re-established its session to the server. Server name: %5 Server address: %7!S! Session ID: %2 Signing used: %8 Encryption used: %9 Guidance: You should expect this event if there was a previous event 30805, but the client successfully resumed the cached connection before the timeout expired. |
| 0xb0037858 | 11 | The connection to the share was re-established. Share name: %5 Server address: %7!S! Session ID: %2 Tree ID: %3 Signing used: %8 Encryption used: %9 Guidance: You should expect this event if there was a previous event 30807, but the client successfully resumed the cached connection before the timeout expired. |
| 0xb0047853 | 11 | Failed to establish a network connection. Error: %2 Server name: %4 Server address: %6!S! Instance name: %9 Connection type: %10 Port origin: %11 Connection ID: %13 Client certificate thumbprint: %15 Guidance: This indicates a problem with the underlying network or transport, such as with TCP/IP or QUIC/UDP, and not with SMB. A firewall that blocks the TCP or UDP port listed in the Server Address field can also cause this issue. |
| 0xb0047858 | 11 | The connection to the share was re-established. Share name: %5 Server address: %7!S! Session ID: %2 Tree ID: %3 Transport type: %8 Signing used: %9 Encryption used: %10 Compression requested: %11 NTLM blocked: %12 Guidance: You should expect this event if there was a previous event 30807, but the client successfully resumed the cached connection before the timeout expired. |
| 0xd000000a | 11 | NetBT |
| 0xd000000b | 11 | TCPIP |
| 0xd000001b | 11 | Smb2DiagReasonQuicServerCertificateValidationError |
| 0xd000001c | 11 | Smb2DiagReasonAcquireCredHandle |
| 0xd000001d | 11 | Smb2DiagReasonISC |
| 0xd000001e | 11 | Smb2DiagReasonSessionSetupResponse |
| 0xd000001f | 11 | Smb2DiagReasonMADowngrade |
| 0xd0000020 | 11 | Smb2DiagReasonCreateSigningKey |
| 0xd0000021 | 11 | Smb2DiagReasonRegisterCryptoKeys |
| 0xd0000022 | 11 | Smb2DiagReasonQCA |
| 0xd0000023 | 11 | Smb2DiagReasonEncryptionOnNullSession |
| 0xd0000024 | 11 | Smb2DiagReasonSessionKeyLength |
| 0xd0000025 | 11 | Smb2DiagReasonTreeConnectResponse |
| 0xd0000026 | 11 | Smb2DiagReasonValidateNegotiateFsctl |
| 0xd0000027 | 11 | Smb2DiagReasonHandleReconnect |
| 0xd0000028 | 11 | Smb2DiagReasonCreateResponse |
| 0xd0000029 | 11 | Smb2DiagReasonExchangeCancellation |
| 0xd000002a | 11 | Smb2DiagReasonExchangeNoBindingObject |
| 0xd000002b | 11 | Smb2DiagReasonExchangeSendFailure |
| 0xd000002c | 11 | Smb2DiagReasonObjectSuspended |
| 0xd000002d | 11 | Smb2DiagReasonUserDisconnect |
| 0xd000002e | 11 | Smb2DiagReasonHandleClosed |
| 0xd000002f | 11 | Smb2DiagReasonInternalError |
| 0xd0000030 | 11 | Smb2DiagDisconnectReasonReceiveContextAllocation |
| 0xd0000031 | 11 | Smb2DiagDisconnectReasonPaddingAllocation |
| 0xd0000032 | 11 | Smb2DiagDisconnectReasonExchangeReceiveHandlerError |
| 0xd0000033 | 11 | Smb2DiagDisconnectReasonMessageBufferAllocation |
| 0xd0000034 | 11 | Smb2DiagDisconnectReasonVcEndpointTornDown |
| 0xd0000035 | 11 | Smb2DiagDisconnectReasonMessageSizeReceiveError |
| 0xd0000036 | 11 | Smb2DiagDisconnectReasonMessageSizeTooLargeError |
| 0xd0000037 | 11 | Smb2DiagDisconnectReasonMessageCopyError |
| 0xd0000038 | 11 | Smb2DiagDisconnectReasonVcReceiveHandlerError |
| 0xd0000039 | 11 | Smb2DiagDisconnectReasonVcReceiveError |
| 0xd000003a | 11 | Negotiate |
| 0xd000003b | 11 | Session setup |
| 0xd000003c | 11 | Logoff |
| 0xd000003d | 11 | Tree connect |
| 0xd000003e | 11 | Tree disconnect |
| 0xd000003f | 11 | Create |
| 0xd0000040 | 11 | Close |
| 0xd0000041 | 11 | Flush |
| 0xd0000042 | 11 | Read |
| 0xd0000043 | 11 | Write |
| 0xd0000044 | 11 | Lock |
| 0xd0000045 | 11 | Ioctl |
| 0xd0000046 | 11 | Cancel |
| 0xd0000047 | 11 | Echo |
| 0xd0000048 | 11 | Query directory |
| 0xd0000049 | 11 | Change notify |
| 0xd000004a | 11 | Query info |
| 0xd000004b | 11 | Set info |
| 0xd000004c | 11 | Oplock break |
| 0xd000004d | 11 | Create |
| 0xd000004e | 11 | Close |
| 0xd000004f | 11 | Read |
| 0xd0000050 | 11 | Write |
| 0xd0000051 | 11 | Query information |
| 0xd0000052 | 11 | Set information |
| 0xd0000053 | 11 | Query EA |
| 0xd0000054 | 11 | Set EA |
| 0xd0000055 | 11 | Flush buffers |
| 0xd0000056 | 11 | Query volume information |
| 0xd0000057 | 11 | Set volume information |
| 0xd0000058 | 11 | Directory control |
| 0xd0000059 | 11 | File system control |
| 0xd000005a | 11 | Device control |
| 0xd000005b | 11 | Internal device control |
| 0xd000005c | 11 | Lock control |
| 0xd000005d | 11 | Cleanup |
| 0xd000005e | 11 | Query security |
| 0xd000005f | 11 | Set security |
| 0xd0000060 | 11 | Query quota information |
| 0xd0000061 | 11 | Set quota information |
| 0xd0000062 | 11 | Internal probe I/O |
| 0xd0000063 | 11 | Symmetric |
| 0xd0000064 | 11 | Asymmetric |
| 0xd0000065 | 11 | None |
| 0xd0000066 | 11 | NTLM |
| 0xd0000067 | 11 | Kerberos |
| 0xd0000068 | 11 | PKU2U |
| 0xd0000069 | 11 | RDR_PRIMARY_INSTANCE |
| 0xd000006a | 11 | RDR_CSV_INSTANCE |
| 0xd000006b | 11 | RDR_SBL_INSTANCE |
| 0xd000006c | 11 | RDR_SR_INSTANCE |
| 0xd000006d | 11 | Security Transforms Disabled |
| 0xd000006e | 11 | Security Transforms Enabled |
| 0xd000006f | 11 | Security Transforms Enabled (Except For Shares Enabled With Isolated Transport) |
| 0xd0000070 | 11 | The port was not selected for this transport. |
| 0xd0000071 | 11 | The port was selected from the |
| 0xd0000072 | 11 | The port was selected from net use parameters. |
| 0xd0000073 | 11 | The port was selected from the device instance's configuration. |
| 0xd0000074 | 11 | The port was selected from the global registry settings. |
| 0xd0000075 | 11 | The port was selected from the |
| 0xd0000076 | 11 | InitializeSecurityContextW |
| 0xd0000077 | 11 | AcquireCredentialsHandleW |
| 0xf0000001 | 11 | Supports RDMA via SMBDirect |
| 0xf0000002 | 11 | Supports runtime unlinking from SMBDirect |
| 604 entries | ||