srv2.sys
Associated Error Codes
Below lists error codes and symbolic names found for this module.
| Code | Found in | Description |
|---|---|---|
| 0x10000035 | 1011 | Audit Failure |
| 0x30000000 | 1011 | Info |
| 0x30000001 | 1011 | Start |
| 0x30000002 | 1011 | Stop |
| 0x30000009 | 1011 | Send |
| 0x50000002 | 1011 | Error |
| 0x50000003 | 1011 | Warning |
| 0x50000004 | 1011 | Information |
| 0x90000001 | 1011 | Microsoft-Windows-SMBServer/Performance |
| 0x90000002 | 1011 | Microsoft-Windows-SMBServer/Analytic |
| 0x90000003 | 1011 | Microsoft-Windows-SMBServer/Operational |
| 0x90000004 | 1011 | Microsoft-Windows-SMBServer/Diagnostic |
| 0x90000005 | 1011 | Microsoft-Windows-SMBServer/Security |
| 0x90000006 | 1011 | Microsoft-Windows-SMBServer/Connectivity |
| 0x90000007 | 1011 | Microsoft-Windows-SMBServer/Audit |
| 0xb00000c8 | 1011 | SMB2 Work Item Component Transition |
| 0xb00000c9 | 1011 | SMB2 Work Item allocated |
| 0xb00000ca | 1011 | SMB2 Work Item released |
| 0xb00000cb | 1011 | SMB2 Work Item activity id transfer |
| 0xb00000cc | 1011 | SMB2 Work Item external activity id stop |
| 0xb00001f4 | 1011 | SMB2 Connection accepted |
| 0xb00001f5 | 1011 | SMB2 Connection Disconnected by Peer |
| 0xb00001f6 | 1011 | SMB2 Connection Terminated |
| 0xb0000226 | 1011 | SMB2 Session Allocated |
| 0xb0000227 | 1011 | Smb Session Authentication Failure |
| 0xb0000228 | 1011 | SMB2 Session Authentication Success |
| 0xb0000229 | 1011 | SMB2 Session Bound to Connection |
| 0xb000022a | 1011 | SMB2 Session Terminated |
| 0xb000022b | 1011 | SMB2 Session Closed. |
| 0xb0000258 | 1011 | SMB2 TreeConnect Allocated |
| 0xb0000259 | 1011 | SMB2 TreeConnect Disconnected |
| 0xb000025a | 1011 | SMB2 TreeConnect Terminated |
| 0xb000025b | 1011 | SMB2 TreeConnect Failed due to Cluster Endpoint Initializing |
| 0xb000028a | 1011 | SMB2 Open established |
| 0xb000028b | 1011 | SMB2 Open Disconnected - Preserved |
| 0xb000028c | 1011 | SMB2 Open Reconnected |
| 0xb000028d | 1011 | SMB2 Open Suspended - Preserved |
| 0xb000028e | 1011 | SMB2 Open Closed |
| 0xb000028f | 1011 | SMB2 Open Timed Out |
| 0xb0000290 | 1011 | SMB2 Open Terminated |
| 0xb0000291 | 1011 | SMB2 Open Clustered Client Failover Closed |
| 0xb0000292 | 1011 | File handle for file "%8\%2" was invalidated by user %4 from computer %6 |
| 0xb00002bc | 1011 | SMB2 Share Added |
| 0xb00002bd | 1011 | SMB2 Share Modified |
| 0xb00002be | 1011 | SMB2 Share Deleted |
| 0xb00003e8 | 1011 | S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims. This may be expected if the account is not a domain account. |
| 0xb00003e9 | 1011 | SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled. |
| 0xb00003ea | 1011 | RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request. |
| 0xb00003eb | 10 | The server received an unencrypted message from client %4. Message was rejected. Guidance: This event indicates that a client is sending unencrypted data even though the SMB share requires encryption. |
| 0xb00003ec | 10 | The server received an incorrectly signed message from client %2. Message was rejected. Guidance: This event indicates that a client is sending an incorrectly signed request. |
| 0xb00003ed | 1011 | The server failed to validate negotiation from client %2. Connection was terminated. |
| 0xb00003ee | 1011 | The share denied access to the client. Client Name: %10 Client Address: %6 User Name: %8 Session ID: %17 Share Name: %2 Share Path: %4 Status: %16 (%15) Mapped Access: %11 Granted Access: %12 Security Descriptor: %14 Guidance: You should expect access denied errors when a principal accesses a share without the necessary permissions. Usually, this indicates that the principal does not have direct security permissions or lacks membership in a group that has direct access permissions. To determine and correct the permissions on the specified share, an administrator can use the Security tab in File Explorer Properties dialog, the SMBSHARE Windows PowerShell module, or the NET SHARE command. You can also use the Effective Access tab in File Explorer to help diagnose the issue. Applications may generate access denied errors if they attempt to open files in a writable mode first, and then reopen the files in a read-only mode. In this case, no user action is required. If access to the share is denied and this event is not logged, you can examine the file and folder NTFS/REFS permissions. This error does not indicate a problem with authentication, only authorization. |
| 0xb00003ef | 1011 | The share denied anonymous access to the client. Client Name: %8 Client Address: %6 Share Name: %2 Share Path: %4 Guidance: You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, anonymous access to shares is denied. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients. |
| 0xb00003f1 | 1011 | The server denied anonymous access to the client. Client Name: %4 Client Address: %2 Session ID: %5 Guidance: You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, Windows Server denies anonymous access to shares. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients. |
| 0xb00003f2 | 1011 | Endpoint added. Name: %2 Domain Name: %4 Transport Name: %6 Transport Flags: %7 Guidance: You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network adaptor. No user action is required. |
| 0xb00003f3 | 1011 | Endpoint removed. Name: %2 Domain Name: %4 Transport Name: %6 Guidance: You should expect this event when the server stops listening on an interface, such as during shutdown or when disabling a network adaptor. No user action is required. |
| 0xb00003f4 | 1011 | The network name information changed. Change Type: %1 Net Name: %3 IP Address: %9 Flags: %4 Interface Index: %5 Capability: %6 Link Speed: %7 Guidance: You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network configuration. No user action is required. |
| 0xb00003f5 | 1011 | Endpoint coming online. Endpoint Name: %2 Transport Name: %4 Guidance: You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required. |
| 0xb00003f6 | 1011 | Endpoint going offline. Endpoint Name: %2 Transport Name: %4 Guidance: You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required. |
| 0xb00003f7 | 1011 | Decrypt call failed. Client Name: %2 Client Address: %4 Session ID: %7 Status: %6 (%5) Guidance: This event commonly occurs because a previous SMB session no longer exists. It may also be caused by packets that are altered on the network between the computers due to either errors or a "man-in-the-middle" attack. |
| 0xb00003f8 | 1011 | Reopen failed. Client Name: %7 Client Address: %9 User Name: %13 Session ID: %14 Share Name: %11 File Name: %16 Resume Key: %20 Status: %2 (%1) RKF Status: %4 (%3) Durable: %17 Resilient: %18 Persistent: %19 Reason: %21 Guidance: The client attempted to reopen a continuously available handle, but the attempt failed. This typically indicates a problem with the network or underlying file being re-opened. |
| 0xb00003f9 | 1011 | Handle scavenged. Share Name: %7 File Name: %9 Resume Key: %5 Persistent File ID: %3 Volatile File ID: %4 Durable: %1 Resilient or Persistent: %2 Guidance: The server closed a handle that was previously reserved for a client after 60 seconds. You should expect this event on a computer that is continuously available where a client did not gracefully close its session. For instance, this may occur when the client unexpectedly restarted. |
| 0xb00003fa | 1011 | Backchannel invalidation of session completed. Session ID: %1 Status: %3 (%2) Task Status: %5 (%4) Guidance: You should expect this event on a computer that is continuously available. No user action is required |
| 0xb00003fb | 1011 | Backchannel invalidation of file completed. Resume Key: %1 Status: %3 (%2) Task Status: %5 (%4) Guidance: You should expect this event on a computer that is continuously available. No user action is required |
| 0xb00003fc | 1011 | File system operation has taken longer than expected. Client Name: %8 Client Address: %10 User Name: %6 Session ID: %3 Share Name: %12 File Name: %14 Command: %1 Duration (in milliseconds): %15 Warning Threshold (in milliseconds): %16 Guidance: The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB. |
| 0xb00003fd | 1011 | LmCompatibilityLevel value is different from the default. Configured LM Compatibility Level: %1 Default LM Compatibility Level: %2 Guidance: LAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers. Value (Setting) - Description 0 (Send LM & NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 1 (Send LM & NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication. 4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication. 5 (Send NTLM v2 response only/refuse LM & NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication. Incompatibly configured LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings. |
| 0xb00003fe | 1011 | File and printer sharing firewall rule enabled. Guidance: You should expect this event when Windows Firewall is configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that has custom shares configured. |
| 0xb00003ff | 1011 | One or more shares present on this server have access based enumeration enabled. Guidance: You should expect this event when enabling access-based enumeration on one or more shares by using either Server Manager or the Set-SmbShare Windows PowerShell cmdlet. Access-based enumeration can raise CPU utilization when clients connect to shares with folders containing many peer-level resources to which a user does not have access. You can control the CPU utilization by configuring the ABELevel value in the Windows registry: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters\ABELevel [DWORD] You can set the value for ABELevel to greater depths to minimize CPU overhead, but doing so diminishes the effectiveness of access-based enumeration: Value = 0: access-based enumeration is enabled for all levels Value = 1: access-based enumeration is enabled for a depth of 1 (example: \server\share) Value = 2: access-based enumeration is enabled for a depth of 2 (example: \server\share\folder) You can continue setting values for multiple depth levels. |
| 0xb0000400 | 1011 | SMB2 and SMB3 have been disabled on this server. This results in reduced functionality and performance. Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters Registry Value: Smb2 Default Value: 1 (or not present) Current Value: 0 Guidance: You should expect this event when disabling SMB2/SMB3. Microsoft does not recommend disabling SMB2/SMB3. When SMB3 is disabled, you cannot use features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. In most scenarios, SMB provides a troubleshooting workaround as an alternative to disabling SMB2/SMB3. Use the Set-SmbServerConfiguration Windows PowerShell cmdlet to enable SMB2/SMB3. |
| 0xb0000401 | 1011 | One or more named pipes or shares have been marked for access by anonymous users. This increases the security risk of the computer by allowing unauthenticated users to connect to this server. Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters Registry Values: NullSessionPipes, NullSessionShares Default Value: Empty (or not present) Current Value: Non-empty Guidance: You should expect this event when modifying the default values of NullSessionShares and NullSessionPipes. On a typical file server, these settings do not exist or do not contain values, which is the most secure configuration. By default, domain controllers populate the NullSessionShares entry with netlogon, samr, and lsarpc to allow legacy access methods. |
| 0xb0000402 | 1011 | File leasing has been disabled for the SMB2 and SMB3 protocols. This reduces functionality and can decrease performance. Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters Registry Value: DisableLeasing Default Value: 0 (or not present) Current Value: non-zero Guidance: You should expect this event when disabling SMB 3 Leasing. Microsoft does not recommend disabling SMB Leasing. Once disabled, traffic from client to server may increase since metadata and data may no longer be retrieved from a local cache. |
| 0xb0000403 | 1011 | The file and printer sharing firewall ports are currently closed. This is the default configuration for a system that is not sharing content or is on a Public network. Guidance: You should expect this event when Windows Firewall is not configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that does not have custom shares configured. Clients cannot access SMB shares on this computer until SMB traffic is allowed through the firewall. |
| 0xb0000404 | 1011 | The maximum cluster-supported SMB dialect has changed. NewMaxDialect: %1 OldMaxDialect: %2 Guidance: You should expect this event during a Windows Failover Cluster upgrade. No user action is required. |
| 0xb0000405 | 1011 | The Cipher Suite Order group policy setting is invalid. Guidance: This event indicates that an administrator has configured an invalid value for the "Computer Configuration\Administrative Templates\Network\Lanman Server\Cipher Suite Order" group policy setting. The server will use the default cipher suite order "%1" until this error is resolved. |
| 0xb0000406 | 1011 | An MDL read or write completion request failed. Server Name: %2 Share Name: %4 File Name: %6 IsRead: %7 Status: %8 Guidance: The SMB server sends MDL completion requests to a file system upon completion of a buffered I/O to release system resources. The file system and its filter drivers must not fail MDL completion requests. Failures may result in memory leaks and degraded system performance and stability. Non-Microsoft file system filter drivers are the most common cause of failed MDL completion requests. |
| 0xb0000407 | 1011 | The server detected a problem and has captured a live kernel dump to collect debug information. Reason: %1 Dump Location: %SystemRoot%\LiveKernelReports Guidance: The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected. Stalled I/O An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity. |
| 0xb0000408 | 1011 | The server detected a problem but was unable to capture a live kernel dump to collect debug information. Reason: %1 Guidance: The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected. In this case, the server's request to create a live kernel dump was rejected. This is usually due to the live kernel dump throttle, which prevents frequent dumps from consuming too much disk space. Either wait for the throttle limit to expire (by default, 7 days), or contact Microsoft Support for steps to override the throttle. This event is written to the log no more than once per day. The problem that caused the server to the request a live kernel dump may be occuring more frequently. Stalled I/O An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity. |
| 0xb0000409 | 1011 | Sent RDMA %1 event to LanmanServer for interface %3. |
| 0xb000040a | 1011 | Send RDMA Endpoint notification failure - %1 |
| 0xb000040b | 1011 | RDMA Endpoint %4 for interface %2 was %1. |
| 0xb000040c | 1011 | RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1. %2 |
| 0xb000040d | 1011 | RDMA listener creation failure - %1 |
| 0xb000040e | 1011 | RDMA Send endpoint notification RPC failure for device %3 - %1 |
| 0xb000040f | 1011 | Received Nsi notification type %1 for interface %2 with NdkOperationalState %3 |
| 0xb0000410 | 1011 | Received Mib notification type %1 for interface %2 |
| 0xb0000411 | 1011 | Error reading FSCTL properties information from the registry. Registry value entry %3 will be ignored. Error: %1 |
| 0xb0000412 | 1011 | The certificate for the server is about to expire. Subject: %2 Thumbprint: %4 Expires on %5. Guidance: This event indicates the certificate is about to expire. Renew or issue new certificates to avoid service interruption. |
| 0xb0000413 | 1011 | RDMA connection disconnected. Transport name: %3 Milliseconds spent closing the connection: %1 Guidance: Closing an RDMA connection should not take longer than 2 minutes. An RDMA IO that takes an abnormally long time to complete indicates a problem with the RDMA network adapters on this computer or its remote host. Contact your RDMA vendor for an updated driver and further troubleshooting. |
| 0xb0000414 | 10 | Quic connection shutdown. Error: %1 Reason: %2 Endpoint Name: %4 Transport Name: %6 Guidance: This event indicates that the winquic connection is shuting down by the server. This event commonly occurs because the server certificate mapping is not created. It may also be caused by the server failed to configure the winquic connections. |
| 0xb0000415 | 1011 | The server failed to update server certificate mapping. Name: %2 Subject: %4 Thumbprint: %6 The certificate can't be used for the server due to error %7 The server certificate mapping %9 removed. |
| 0xb0000708 | 1011 | CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share. |
| 0xb0000709 | 1011 | CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to attach to the underlying volume. |
| 0xb000070a | 1011 | The server failed to reserve the next ID region in the cluster registry. |
| 0xb000070b | 1011 | The security descriptor differs from the default value. Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\DefaultSecurity\%1 Guidance: This is typically caused by an administrator or a third party changing the security on the object manually. To reset the security back to the default value, delete the path shown above. Microsoft does not recommend changing the default security of %1 as it may cause application incompatibilities or security concerns. |
| 0xb000076c | 1011 | TDI mode enabled: %1 |
| 0xb000076d | 1011 | Failed to allocate an NSI table for network interface enumeration: %1 |
| 0xb000076e | 1011 | Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23) |
| 0xb000076f | 1011 | Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23) |
| 0xb0000770 | 1011 | Failed to open network interface with Luid %1: error %2 |
| 0xb0000771 | 1011 | The server closed the session as part of periodic system cleanup. Session Id: %1 Instance Id: %2 Reason: %3 |
| 0xb00007d0 | 1011 | Packet Fragment (%2 bytes) |
| 0xb0000bb8 | 1011 | SMB1 access Client Address: %1 Guidance: This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration. |
| 0xb0000bcd | 1011 | The SMB server observed that the client doesn't support signing. Client name: %2 Server requires signing: %3 |
| 0xb0000bd0 | 1011 | The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA is disabled. Client name: %2 SPN Query Status: %3 SPN Validation Policy: %4 |
| 0xb0000bd1 | 1011 | The SMB server observed that the client sent an unrecognized SPN during authentication. Client name: %2 SPN: %3 SPN Validation Policy: %6 |
| 0xb0000bd2 | 1011 | The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one. Client name: %2 SPN Validation Policy: %3 |
| 0xb0000bd3 | 1011 | The SMBv1 server observed that the SMBv1 client does not have signing enabled. Client name: %2 Server requires signing: %3 Guidance: This event indicates that the SMBv1 client may not support SMB signing, but due to protocol limitations, this cannot be determined with certainty. Further evaluation is recommended to verify the client's signing capabilities. Prior to Windows Vista, SMBv1 clients that did not have signing explicitly enabled could not perform SMB signing. This behavior was changed with the release of Windows Vista and was also backported to Windows XP and Windows Server 2003 through updates. With these changes, SMB clients may support signing even if it is not explicitly enabled, provided the server requires it. |
| 0xb0009c40 | 1011 | Packet (%4 bytes) |
| 0xb0010227 | 1011 | SMB Session Authentication Failure Client Name: %11 Client Address: %6 User Name: %9 Session ID: %7 Status: %4 (%3) Guidance: You should expect this error when attempting to connect to shares using incorrect credentials. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients. This error can occur when using incorrect usernames and passwords with NTLM, mismatched LmCompatibility settings between client and server, duplicate Kerberos service principal names, incorrect Kerberos ticket-granting service tickets, or Guest accounts without Guest access enabled |
| 0xb00103e9 | 1011 | A client attempted to access the server using SMB1 and was rejected because SMB1 file sharing support is disabled or has been uninstalled. Guidance: An administrator has disabled or uninstalled server support for SMB1. Clients running Windows XP / Windows Server 2003 R2 and earlier will not be able to access this server. Clients running Windows Vista / Windows Server 2008 and later no longer require SMB1. To determine which clients are attempting to access this server using SMB1, use the Windows PowerShell cmdlet Set-SmbServerConfiguration to enable SMB1 access auditing. |
| 0xb00103eb | 1011 | The server received an unencrypted message from client when encryption was required. Message was rejected. Client Name: %4 Client Address: %8 User Name: %6 Session ID: %9 Share Name: %2 Guidance: This event indicates that a client is sending unencrypted data even though the SMB share requires encryption. |
| 0xb00103ec | 1011 | The server rejected an incorrectly signed message. Client Name: %2 Client Address: %6 User Name: %4 Session ID: %7 Guidance: This event indicates that a client is sending an incorrectly signed request. |
| 0xb00103ed | 1011 | The server rejected an invalid negotiation request. Connection was terminated. Client Name: %2 Client Address: %6 User Name: %4 Session ID: %13 Expected Dialect: %7 Expected Capabilities: %8 Expected Security Mode: %9 Received Dialect: %10 Received Capabilities: %11 Received Security Mode: %12 Guidance: This event indicates that a client is attempting to negotiate a second connection using a mismatched dialect or capabilities. |
| 0xb001070c | 1011 | No SMB1 usage detected in the last 20 minutes. Guidance: This event indicates that no attempt was made to contact this computer via the SMB1 protocol. After %1 online days of no SMB1 contact attempts, the SMB1 Server service will automatically uninstall. |
| 0xb0010bba | 1011 | A remote device attempted SMB1 connection to this computer. Client Address: %1 Guidance: This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration. |
| 0xb0010bbb | 1011 | SMB1 server service has been automatically uninstalled.n Guidance: This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Server service was automatically uninstalled. |
| 0xb0010bcd | 1011 | The SMB server observed that the client doesn't support signing. Client name: %2 User Name: %4 Server requires signing: %5 |
| 0xb0020001 | 1011 | SMB2 Request Negotiate |
| 0xb0020002 | 1011 | SMB2 Request Session Setup |
| 0xb0020003 | 1011 | SMB2 Request Logoff |
| 0xb0020004 | 1011 | SMB2 Request Tree Connect |
| 0xb0020005 | 1011 | SMB2 Request Tree Disconnect |
| 0xb0020006 | 1011 | SMB2 Request Echo |
| 0xb0020007 | 1011 | SMB2 Request Cancel |
| 0xb0020008 | 1011 | SMB2 Request Create |
| 0xb0020009 | 1011 | SMB2 Request Close |
| 0xb002000a | 1011 | SMB2 Request Flush |
| 0xb002000b | 1011 | SMB2 Request Read |
| 0xb002000c | 1011 | SMB2 Request Write |
| 0xb002000d | 1011 | SMB2 Request Break Oplock |
| 0xb002000e | 1011 | SMB2 Request Notify Break Lease |
| 0xb002000f | 1011 | SMB2 Request Acknowledge Break Lease |
| 0xb0020010 | 1011 | SMB2 Request Lock |
| 0xb0020011 | 1011 | SMB2 Request Ioctl |
| 0xb0020012 | 1011 | SMB2 Request Query Directory |
| 0xb0020013 | 1011 | SMB2 Request Change Notify |
| 0xb0020014 | 1011 | SMB2 Request Query Info |
| 0xb0020015 | 1011 | SMB2 Request Set Info |
| 0xb0020065 | 1011 | SMB2 Response Negotiate |
| 0xb0020066 | 1011 | SMB2 Response Session Setup |
| 0xb0020067 | 1011 | SMB2 Response Logoff |
| 0xb0020068 | 1011 | SMB2 Response Tree Connect |
| 0xb0020069 | 1011 | SMB2 Response Tree Disconnect |
| 0xb002006a | 1011 | SMB2 Response Echo |
| 0xb002006c | 1011 | SMB2 Response Create |
| 0xb002006d | 1011 | SMB2 Response Close |
| 0xb002006e | 1011 | SMB2 Response Flush |
| 0xb002006f | 1011 | SMB2 Response Read |
| 0xb0020070 | 1011 | SMB2 Response Write |
| 0xb0020071 | 1011 | SMB2 Response Break Oplock |
| 0xb0020073 | 1011 | SMB2 Response Acknowledge Break Lease |
| 0xb0020074 | 1011 | SMB2 Response Lock |
| 0xb0020075 | 1011 | SMB2 Response Ioctl |
| 0xb0020076 | 1011 | SMB2 Response Query Directory |
| 0xb0020077 | 1011 | SMB2 Response Change Notify |
| 0xb0020078 | 1011 | SMB2 Response Query Info |
| 0xb0020079 | 1011 | SMB2 Response Set Info |
| 0xb002007a | 1011 | SMB2 Response Error |
| 0xb0020227 | 1011 | SMB Session Authentication Failure Client Name: %11 Client Address: %6 User Name: %9 Session ID: %7 Status: %4 (%3) SPN: %12 SPN Validation Policy: %13 Guidance: You should expect this error when attempting to connect to shares using incorrect credentials. This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients. This error can occur when using incorrect usernames and passwords with NTLM, mismatched LmCompatibility settings between client and server, an incorrect service principal name, duplicate Kerberos service principal names, incorrect Kerberos ticket-granting service tickets, or Guest accounts without Guest access enabled |
| 0xb00203ed | 1011 | Negotiate integrity check failed. Status: %2 Client Name: %4 Client Address: %8 User Name: %6 Session ID: %9 Guidance: This event indicates that the client's negotiate request was altered on the network between the client and server due to errors or a "man-in-the-middle" attack. The client has been disconnected to prevent a security downgrade. |
| 0xd0000001 | 1011 | SPN optional / no validation |
| 0xd0000002 | 1011 | SPN optional / validate service name |
| 0xd0000003 | 1011 | SPN optional / validate full |
| 0xd0000004 | 1011 | SPN required / validate service name |
| 0xd0000005 | 1011 | SPN required / validate full |
| 0xd0000006 | 1011 | Stalled I/O |
| 0xd0000007 | 1011 | Reopen durable handle failed |
| 0xd0000008 | 1011 | Tdi |
| 0xd0000009 | 1011 | Wsk |
| 0xd000000a | 1011 | Rdma |
| 0xd000000b | 1011 | Vmbus |
| 0xd000000c | 1011 | Quic |
| 0xd000000d | 1011 | Add |
| 0xd000000e | 1011 | Update |
| 0xd000000f | 1011 | Remove |
| 0xd0000010 | 1011 | None |
| 0xd0000011 | 1011 | Reconnect durable file |
| 0xd0000012 | 1011 | RKF resume create |
| 0xd0000013 | 1011 | Build create response |
| 0xd0000014 | 1011 | N/A |
| 0xd0000015 | 1011 | 2.0.2 |
| 0xd0000016 | 1011 | 2.1 |
| 0xd0000017 | 1011 | 3.0 |
| 0xd0000018 | 1011 | 3.0.2 |
| 0xd0000019 | 1011 | 3.1.1 |
| 0xd000001a | 1011 | closed |
| 0xd000001b | 1011 | created |
| 0xd000001c | 1011 | disabled |
| 0xd000001d | 1011 | enabled |
| 0xd000001e | 1011 | Error getting unicast ip address table for interface %2. %3 |
| 0xd000001f | 1011 | Error getting unicast ip address entry for interface %2. %3 |
| 0xd0000020 | 1011 | Error finding or adding the interface %2. |
| 0xd0000021 | 1011 | DadState is different from IpDadStatePreferred for interface %2. Current DadState: %6. |
| 0xd0000022 | 1011 | Error getting Nsi parameters for interface %2. %3 |
| 0xd0000023 | 1011 | Error allocating pool memory |
| 0xd0000024 | 1011 | Error updating transport list for device %5. %3. |
| 0xd0000025 | 1011 | Error allocating and getting table. %3. |
| 0xd0000026 | 1011 | Notification type %6 is not supported. Nothing was done. |
| 0xd0000027 | 1011 | Error getting Address from TransportName for interface %2. %3 |
| 0xd0000028 | 1011 | Error finding the address of the interface %2. %3 |
| 0xd0000029 | 1011 | Error because SMB Direct is not supported in interface %2. %3 |
| 0xd000002a | 1011 | Error initializing SMB in interface %2. %3 |
| 0xd000002b | 10 | Error initilizing the async handle. %4 |
| 0xd000002c | 10 | XsActSrv is not active. |
| 0xd000002d | 10 | Pnp exception. %4 |
| 0xd000002e | 10 | Timeout on comleting pnp operation. %4 |
| 0xd000002f | 10 | Pnp operation took too long and it was never completed so it must be cancelled. %4 |
| 0xd0000030 | 10 | Error cancelling Pnp opearion. %4 |
| 0xd0000031 | 10 | NsiParameterNotification |
| 0xd0000032 | 10 | NsiAddInstance |
| 0xd0000033 | 10 | NsiDeleteInstance |
| 0xd0000034 | 10 | NsiInitialNotification |
| 0xd0000035 | 10 | MibParameterNotification |
| 0xd0000036 | 10 | MibAddInstance |
| 0xd0000037 | 10 | MibDeleteInstance |
| 0xd0000038 | 10 | MibInitialNotification |
| 0xd0000039 | 10 | Registry value defines properties for an FSCTL that has already been defined in another registry value. |
| 0xd000003a | 10 | Registry value specifying FSCTL properties must also specify a non-zero FSCTL code. |
| 0xd000003b | 10 | Registry value specifying FSCTL properties have the wrong format. |
| 0xd000003c | 10 | Connection state has not changed. |
| 0xd000003d | 10 | Connection timed out. |
| 0xd000003e | 10 | The connection was idle and timed out. |
| 0xd000003f | 10 | The server is stopping. |
| 0xd0000040 | 10 | The endpoint is closing. |
| 0xd0000041 | 10 | The connection is disconnected. |
| 0xd0000042 | 10 | The idle connection is time out. |
| 0xd0000043 | 10 | All channels are closed. |
| 0xd0000044 | 10 | Decrypt message error. |
| 0xd0000045 | 10 | Irrecoverable error. |
| 0xd0000046 | 10 | Unauthenticated connection is closed. |
| 0xd0000047 | 10 | Failed to send an interim async response. |
| 0xd0000048 | 10 | Insufficient resources. |
| 0xd0000049 | 10 | Connection/Stream shutdown without error. |
| 0xd000004a | 10 | Connection/Stream shutdown unknown error. |
| 0xd000004b | 10 | The event received is not supported. |
| 0xd000004c | 10 | Invalid Parameter. |
| 0xd000004d | 10 | The object is not found. |
| 0xd000004e | 10 | Insufficient resources. |
| 0xd000004f | 10 | Server can't create a new connection. |
| 0xd0000050 | 10 | Server can't set bidi stream count for the connection. |
| 0xd0000051 | 10 | Server can't get the local address. |
| 0xd0000052 | 10 | Server close the connection. |
| 0x10000001 | 11 | Request |
| 0x10000002 | 11 | Response |
| 0x10000003 | 11 | Transition |
| 0x10000004 | 11 | Operational |
| 0x10000005 | 11 | Connection |
| 0x10000006 | 11 | Session |
| 0x10000007 | 11 | TreeConnect |
| 0x10000008 | 11 | File |
| 0x10000009 | 11 | Share |
| 0x1000000a | 11 | Nsi |
| 0x1000000b | 11 | Cert |
| 0x1000000c | 11 | Quic |
| 0x1000000d | 11 | Correlation |
| 0x10000011 | 11 | Rundown |
| 0x10000012 | 11 | ListenerRule |
| 0x10000013 | 11 | Interface |
| 0x10000014 | 11 | PerfOptional |
| 0x1000001f | 11 | PacketStart |
| 0x10000020 | 11 | PacketEnd |
| 0x10000021 | 11 | SendPath |
| 0x10000022 | 11 | ReceivePath |
| 0x1000002b | 11 | Packet |
| 0x10000030 | 11 | PduFull |
| 0x70000001 | 11 | Smb2RequestNegotiate |
| 0x70000002 | 11 | Smb2RequestSessionSetup |
| 0x70000003 | 11 | Smb2RequestLogoff |
| 0x70000004 | 11 | Smb2RequestTreeConnect |
| 0x70000005 | 11 | Smb2RequestTreeDisconnect |
| 0x70000006 | 11 | Smb2RequestEcho |
| 0x70000007 | 11 | Smb2RequestCancel |
| 0x70000008 | 11 | Smb2RequestCreate |
| 0x70000009 | 11 | Smb2RequestClose |
| 0x7000000a | 11 | Smb2RequestFlush |
| 0x7000000b | 11 | Smb2RequestRead |
| 0x7000000c | 11 | Smb2RequestWrite |
| 0x7000000d | 11 | Smb2RequestBreakOplock |
| 0x7000000e | 11 | Smb2RequestNotifyBreakLease |
| 0x7000000f | 11 | Smb2RequestAcknowledgeBreakLease |
| 0x70000010 | 11 | Smb2RequestLock |
| 0x70000011 | 11 | Smb2RequestIoctl |
| 0x70000012 | 11 | Smb2RequestQueryDirectory |
| 0x70000013 | 11 | Smb2RequestChangeNotify |
| 0x70000014 | 11 | Smb2RequestQueryInfo |
| 0x70000015 | 11 | Smb2RequestSetInfo |
| 0x70000065 | 11 | Smb2ResponseNegotiate |
| 0x70000066 | 11 | Smb2ResponseSessionSetup |
| 0x70000067 | 11 | Smb2ResponseLogoff |
| 0x70000068 | 11 | Smb2ResponseTreeConnect |
| 0x70000069 | 11 | Smb2ResponseTreeDisconnect |
| 0x7000006a | 11 | Smb2ResponseEcho |
| 0x7000006c | 11 | Smb2ResponseCreate |
| 0x7000006d | 11 | Smb2ResponseClose |
| 0x7000006e | 11 | Smb2ResponseFlush |
| 0x7000006f | 11 | Smb2ResponseRead |
| 0x70000070 | 11 | Smb2ResponseWrite |
| 0x70000071 | 11 | Smb2ResponseBreakOplock |
| 0x70000073 | 11 | Smb2ResponseAcknowledgeBreakLease |
| 0x70000074 | 11 | Smb2ResponseLock |
| 0x70000075 | 11 | Smb2ResponseIoctl |
| 0x70000076 | 11 | Smb2ResponseQueryDirectory |
| 0x70000077 | 11 | Smb2ResponseChangeNotify |
| 0x70000078 | 11 | Smb2ResponseQueryInfo |
| 0x70000079 | 11 | Smb2ResponseSetInfo |
| 0x7000007a | 11 | Smb2ResponseError |
| 0x700000c8 | 11 | Smb2WorkItemTransition |
| 0x700000c9 | 11 | Smb2WorkItemStart |
| 0x700000ca | 11 | Smb2WorkItemStop |
| 0x700000cb | 11 | Smb2WorkItemActivityTransfer |
| 0x700000cc | 11 | Smb2WorkItemActivityStop |
| 0x700001f4 | 11 | Smb2ConnectionAccept |
| 0x700001f5 | 11 | Smb2ConnectionDisconnectEvent |
| 0x700001f6 | 11 | Smb2ConnectionTerminate |
| 0x70000226 | 11 | Smb2SessionAllocate |
| 0x70000227 | 11 | Smb2SessionAuthFailure |
| 0x70000228 | 11 | Smb2SessionAuthenticated |
| 0x70000229 | 11 | Smb2SessionBind |
| 0x7000022a | 11 | Smb2SessionTerminate |
| 0x7000022b | 11 | Smb2SessionClose |
| 0x70000258 | 11 | Smb2TreeConnectAllocate |
| 0x70000259 | 11 | Smb2TreeConnectDisconnect |
| 0x7000025a | 11 | Smb2TreeConnectTerminate |
| 0x7000025b | 11 | Smb2TreeConnectFailedDueToPending |
| 0x7000025c | 11 | Smb2TreeConnectForceClientReconnect |
| 0x7000028a | 11 | Smb2FileOpen |
| 0x7000028b | 11 | Smb2FileDisconnect |
| 0x7000028c | 11 | Smb2FileReconnect |
| 0x7000028d | 11 | Smb2FileSuspend |
| 0x7000028e | 11 | Smb2FileClose |
| 0x7000028f | 11 | Smb2FileTimeout |
| 0x70000290 | 11 | Smb2FileTerminate |
| 0x70000291 | 11 | Smb2FileCCFClose |
| 0x70000292 | 11 | Smb2FileCCFCloseAudit |
| 0x700002bc | 11 | Smb2ShareAdd |
| 0x700002bd | 11 | Smb2ShareModify |
| 0x700002be | 11 | Smb2ShareDelete |
| 0x70000384 | 11 | SrvEmptyParameterTemplate |
| 0x700003e8 | 11 | SrvS4U2SelfFailure |
| 0x700003e9 | 11 | SrvDisabled |
| 0x700003ea | 11 | Smb2RkfFailure |
| 0x700003eb | 11 | SrvUnencryptedAcccessFailure |
| 0x700003ec | 11 | SrvSignatureValidationFailure |
| 0x700003ed | 11 | SrvNegotiateValidationFailure |
| 0x700003ee | 11 | SrvShareAccessCheckFailure |
| 0x700003ef | 11 | SrvShareAnonymousAccessDeniedFailure |
| 0x700003f1 | 11 | SrvSessionAnonymousAccessDenied |
| 0x700003f2 | 11 | SrvEndpointAdded |
| 0x700003f3 | 11 | SrvEndpointRemoved |
| 0x700003f4 | 11 | SrvNetNameInfoChange |
| 0x700003f5 | 11 | SrvEndpointOnline |
| 0x700003f6 | 11 | SrvEndpointOffline |
| 0x700003f7 | 11 | SrvDecryptionFailure |
| 0x700003f8 | 11 | SrvReopenFailure |
| 0x700003f9 | 11 | SrvHandleScavenge |
| 0x700003fa | 11 | SrvSessionInvalidate |
| 0x700003fb | 11 | SrvFileInvalidate |
| 0x700003fc | 11 | SrvSlowFsOperation |
| 0x700003fd | 11 | SrvLmCompatibilityLevelNonDefault |
| 0x700003fe | 11 | SrvFileSharingFirewallRuleEnabled |
| 0x700003ff | 11 | SrvABESharesPresent |
| 0x70000400 | 11 | SrvSmb2Disabled |
| 0x70000401 | 11 | SrvNullSessionsAllowed |
| 0x70000402 | 11 | SrvLeasingDisabled |
| 0x70000403 | 11 | SrvFirewallPortsClosed |
| 0x7000041e | 11 | SrvSlowNetworkOperation |
| 0x70000708 | 11 | SSClusterCaFailure |
| 0x70000709 | 11 | SSRkfCaFailure |
| 0x700007d0 | 11 | SrvNetGetNextIdFailure |
| 0x700007d1 | 11 | SrvNetConnectionEstablished |
| 0x700007d2 | 11 | SrvNetClientCertificateChainRevocationChecksFailed |
| 0x70000bbc | 11 | SrvAdminFileRundown |
| 0x70000bbd | 11 | SrvAdminSessionRundown |
| 0x70000bbe | 11 | SrvAdminShareRundown |
| 0x70000bbf | 11 | Smb2MaxClusterDialectUpdated |
| 0x70000bc0 | 11 | Smb2CipherSuiteOrder |
| 0x70000bc1 | 11 | Smb2MdlIoCompletionFailure |
| 0x70000bc2 | 11 | Srv2LiveDumpSucceeded |
| 0x70000bc3 | 11 | Srv2LiveDumpThrotteled |
| 0x70000bc4 | 11 | Srv2RDMASendEndpointNotification |
| 0x70000bc5 | 11 | Srv2RDMASendEndpointNotificationFailure |
| 0x70000bc6 | 11 | Srv2RDMAEndpointChange |
| 0x70000bc7 | 11 | Srv2RDMAEndpointAllocationFailure |
| 0x70000bc8 | 11 | Srv2RDMACreateListenerFailure |
| 0x70000bc9 | 11 | Srv2RDMASendEndpointNotificationRPCFailure |
| 0x70000bca | 11 | Srv2RDMANsiNotificationReceived |
| 0x70000bcb | 11 | Srv2RDMAMibNotificationReceived |
| 0x70000bcc | 11 | SrvAdminFsctlPropertiesListReadingFailure |
| 0x70000bcd | 11 | SrvNetRdmaConnectionClosed |
| 0x70000bce | 11 | ServerCertMappingExpiring |
| 0x70000bcf | 11 | SrvNetQuicShutdownFailure |
| 0x70000bd0 | 11 | ServerCertMappingUpdateFailure |
| 0x70000bd1 | 11 | SrvNoNegotiatedCipher |
| 0x70000bd2 | 11 | Smb2SlowCommand |
| 0x70000bd3 | 11 | Smb2CommandTimeDistribution |
| 0x70000bd4 | 11 | ServerCertMappingExpired |
| 0x70000bd5 | 11 | Smb2ClosedEndpointsOutsideUnicastIPTable |
| 0x70000bd6 | 11 | SrvNegotiateCipherFailure |
| 0x70000bd7 | 11 | ServerCertMappingRestoreFailure |
| 0x70000bd8 | 11 | ServerCertMappingRestoreSummary |
| 0x70000bd9 | 11 | SrvNetRdmaRundownActive |
| 0x70000bda | 11 | SrvNetRdmaRundownComplete |
| 0x70000bdb | 11 | SrvNetRdmaReactivation |
| 0x70000bdc | 11 | SrvNetRdmaReactivationComplete |
| 0x70000bdd | 11 | SrvNetSmbDirectLoad |
| 0x70000bde | 11 | Smb2DirectDataPlacementSecurityChanged |
| 0x70000bdf | 11 | Smb2DialectChange |
| 0x70000be0 | 11 | SecurityCertificateChanged |
| 0x70000be1 | 11 | NoSmb1ObservedInLastPeriod |
| 0x70000be2 | 11 | TdiModeEnabled |
| 0x70000be3 | 11 | NsiTableAllocationFailed |
| 0x70000be4 | 11 | NsiInterfaceAdded |
| 0x70000be5 | 11 | NsiInterfaceRemoved |
| 0x70000be6 | 11 | IPInterfaceNotFound |
| 0x70000be7 | 11 | Srv2SessionKeyTooShort |
| 0x70000be8 | 11 | ReceivedNullReparseBuffer |
| 0x70000be9 | 11 | AllowListLoadFailed |
| 0x70000bea | 11 | SrvNetQuicSendEndpointNotificationFailure |
| 0x70000beb | 11 | SrvNetEventDisableRdmaListenSocketsState |
| 0x70000bec | 11 | ServerCertificateFailure |
| 0x70000bed | 11 | ShareQosPolicySettingFailure |
| 0x70000bee | 11 | PacketFragment |
| 0x70000bef | 11 | Packet |
| 0x70000bf0 | 11 | AuditSmb1Access |
| 0x70000bf1 | 11 | UninstallSmb1Server |
| 0x70000bf2 | 11 | MutualAuthClientAccessDenied |
| 0x70000bf3 | 11 | MutualAuthClientAccessAllowed |
| 0x70000bf4 | 11 | SrvAdminMutualAuthClientAccessErrorShareRundown |
| 0x70000bf5 | 11 | SrvNetAddEndpointListenerRulePortNotSupported |
| 0x70000bf6 | 11 | SrvNetAddEndpointListenerRuleSuccess |
| 0x70000bf7 | 11 | SrvNetAddEndpointListenerRuleFailure |
| 0x70000bf8 | 11 | SrvNetAddListenerRuleNew |
| 0x70000bf9 | 11 | SrvNetAddListenerRuleUpdate |
| 0x70000bfa | 11 | SrvNetAddListenerRuleRemove |
| 0x70000bfb | 11 | SrvNetEnableImplicitLoopbackInterfaceError |
| 0x70000bfc | 11 | SrvNetDisableImplicitLoopbackInterfaceError |
| 0x70000bfd | 11 | SrvNetComponentCapabilities |
| 0x70000bfe | 11 | AlternativePortFirewallRuleAlreadyAdded |
| 0x70000bff | 11 | AlternativePortFirewallRuleAddFailure |
| 0x70000c00 | 11 | AlternativePortFirewallRuleAddSuccess |
| 0x70000c01 | 11 | Smb2ClientDoesNotSupportSigning |
| 0x70000c02 | 11 | Smb2ClientDoesNotSupportEncryption |
| 0x70000c03 | 11 | InsecureGuestLogon |
| 0x70000c04 | 11 | Smb2ShareConnectionEstablished |
| 0x70000c05 | 11 | SrvNetClientDoesNotSupportSpn |
| 0x70000c06 | 11 | SrvNetClientSentUnrecognizedSpn |
| 0x70000c07 | 11 | SrvNetClientSentEmptySpn |
| 0x70000c08 | 11 | Smb1ClientDoesNotSupportSigning |
| 0xb000025c | 11 | A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best possible storage connectivity. Session ID: %1 TreeConnect ID: %2 Share: %4 |
| 0xb000025d | 11 | A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best possible storage connectivity. Session ID: %1 TreeConnect ID: %2 Share: %4 |
| 0xb00003eb | 11 | The server received an unencrypted message. Message was rejected. Client Name: %4 Guidance: This event indicates that a client is sending unencrypted data even though the SMB share requires encryption. |
| 0xb00003ec | 11 | The server received an incorrectly signed message. Message was rejected. Client Name: %2 Guidance: This event indicates that a client is sending an incorrectly signed request. |
| 0xb0000414 | 11 | Quic connection shutdown. Error: %1 Reason: %2 Endpoint Name: %4 Transport Name: %6 Guidance: This event indicates that the winquic connection is shutting down by the server. This event commonly occurs because the server certificate mapping is not created. It may also be caused by the server failed to configure the winquic connections. |
| 0xb0000416 | 11 | The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server allow unencrypted access. Request: %10 Client Name: %4 Client Address: %8 User Name: %6 Session ID: %9 Share Name: %2 Guidance: This event indicates that client is trying to access a server that requires encryption, but no cipher was negotiated, and server does not allow unencrypted access. Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\RejectUnencryptedAccess to see if the value has been changed. |
| 0xb0000417 | 11 | The server received a %2 request but is taking an abnormal amount of time to process it. Instance Id: %1 Command: %2 PerfBlock: %3 Duration(s): %4 Threshold(s): %5 |
| 0xb0000418 | 11 | The server processed a %1 request. Times taken to complete each stage below. Command: %1 AcquireLockTime(s): %2 IoTime(s): %3 TotalTime(s): %4 Threshold(s): %5 |
| 0xb0000419 | 11 | The certificate for the server has expired. Subject: %2 Thumbprint: %4 Expires on %5. Guidance: This event indicates the certificate has expired. Renew or issue new certificates to avoid service interruption. |
| 0xb000041a | 11 | Found %1 endpoint(s) related to interface ID %2, closed %3 of which. |
| 0xb000041b | 11 | The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server. Please ensure there is a common cipher between the client and server. Client encryption cipher suite order (most to least preferred): %2 Server encryption cipher suite order (most to least preferred): %4 |
| 0xb000041c | 11 | Failed to restore a server certificate mapping from persistent storage. Subject: %2 Thumbprint: %4 Error code: %5. |
| 0xb000041d | 11 | Restored %2 of %1 server certificate mappings from persistent storage. Last error code: %3. |
| 0xb000041e | 11 | Network operation has taken longer than expected. Client Name: %8 Client Address: %10 User Name: %6 Session ID: %3 Share Name: %12 File Name: %14 Command: %1 Duration (in milliseconds): %15 Warning Threshold (in milliseconds): %16 Guidance: The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB. |
| 0xb000041f | 11 | RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently %1 active RDMA resources. |
| 0xb0000420 | 11 | RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: %1. |
| 0xb0000421 | 11 | Reactivation of RDMA support has commenced. |
| 0xb0000422 | 11 | RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: %1. |
| 0xb0000423 | 11 | SMBDirect load attempt complete. Success: %1 Status code: %2 Service path: %4 |
| 0xb0000424 | 11 | SMB DDP security changed from %1 to %2. |
| 0xb0000425 | 11 | SMB2 Request Negotiate Dialect Failure Session ID: %1 Client Address: %18 Client Name:%20 Client Dialects: %12 Minimum dialect required by server: %15 Maximum dialect required by server: %16 Guidance: You should expect this error when servers don't meet the dialects requested by client. Please check the minimum and maximum dialects set by the client and ensure the server supports the dialects. |
| 0xb0000426 | 11 | SMB Dialect Change %1 was changed from %2 to %3. |
| 0xb0000438 | 11 | Component capabilities: %1 Internal patch number: %2 |
| 0xb0000772 | 11 | Session key for connection is weaker than required. Connection will be closed as a result. Client: %2 User: %6 Session key length: %3 Required Session key length: %4 Guidance: To establish a connection with a shorter session key, set the following registry DWORD value name with the value as decimal bits: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters] "MinimumSessionKeyLength" Important: If you have configured the 'Network security: Configure encryption types allowed for Kerberos' security policy to prevent use of 256-bit keys but also set the MinimumSessionKeyLength greater than 128 bits, the computer will not be able to make SMB connections. Setting MinimumSessionKeyLength higher than 128 bits will also prevent SMB connections using NTLM. |
| 0xb0000773 | 11 | Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL. |
| 0xb0000774 | 11 | Custom FSCTL allow list was not successfully loaded after several retries. |
| 0xb0000775 | 11 | Send QUIC Endpoint notification failure - %1 |
| 0xb0000776 | 11 | RDMA listen socket disable override is %1. New value is %2. SrvNetIsRDMASupportEnabled is %3. Action taken %4. |
| 0xb0000777 | 11 | Server Certificate failure - %1 |
| 0xb0000778 | 11 | Warning to set the QoS policy on file %6. Status=%1 |
| 0xb0000779 | 11 | The SMB connection was successfully established. Endpoint Name: %2 Transport: %3 Server socket address: %5 Client socket address: %7 Connection ID: %9 Mutual authentication: %10 Access control: %11 |
| 0xb000077a | 11 | The server was unable to perform revocation checks on the client certificate chain. The connection will proceed. Verification Status: %1 Endpoint Name: %3 Transport: %4 Server socket address: %6 Client socket address: %8 Connection ID: %10 |
| 0xb0000bbc | 11 | SMB server admin file rundown |
| 0xb0000bbd | 11 | SMB server admin session rundown |
| 0xb0000bbe | 11 | SMB server admin share rundown |
| 0xb0000bbf | 11 | Access Denied Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server denied access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243808 |
| 0xb0000bc0 | 11 | Access Allowed Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server allowed access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243809 |
| 0xb0000bc1 | 11 | An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: %1 Server certificate mapping name: %3 Client socket address: %5 Guidance: For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243709 |
| 0xb0000bc2 | 11 | An administrator attempted to assign an alternative SMB server listener port %1, but it is either in the 0―1024 reserved range or it is already assigned to another process. Use NETSTAT -abno to list all listening ports and their processes in use on this computer. |
| 0xb0000bc3 | 11 | The SMB server service created an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvInstances: %5 Guidance: You should expect this event when assigning alternative SMB server listener ports and on any subsequent restarts of the SMB server service. |
| 0xb0000bc4 | 11 | The SMB server service failed to create an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvInstances: %5 Error: %6 Guidance: This error is usually caused by another process already listening on the same IP address and port. Use NETSTAT -abno to list all listening ports and their processes in use on this computer. |
| 0xb0000bc5 | 11 | An administrator created an alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clients can now connect to this alternative SMB server listener port. |
| 0xb0000bc6 | 11 | An administrator updated an existing alterative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clients can now connect to this updated alternative SMB server listener port. |
| 0xb0000bc7 | 11 | An administrator removed an existing alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: This will close the specified listening sockets for the transport type on the specified port number. SMB clients cannot connect to this SMB server on that alternative port anymore. |
| 0xb0000bc8 | 11 | The SMB server service failed to enable an implicit loopback interface for interface %1 with NTSTATUS %2. |
| 0xb0000bc9 | 11 | The SMB server service failed to disable an implicit loopback interface for interface %1 with NTSTATUS %2. |
| 0xb0000bca | 11 | The inbound %2 firewall rule already exists for port %1. |
| 0xb0000bcb | 11 | The inbound %2 firewall rule failed to be created for port %1. |
| 0xb0000bcc | 11 | The inbound %2 firewall rule was successfully created for port %1. |
| 0xb0000bce | 11 | The SMB server observed that the client doesn't support encryption. Client name: %2 Server requires encryption: %3 |
| 0xb0000bcf | 11 | The SMB client was logged on as Guest account. Client name: %2 |
| 0xb0000fa0 | 11 | The SMB client connection to the share was established. Share name: %2 Client name: %6 Client address: %4 Session ID: %7 Tree ID: %8 Transport type: %9 Signing used: %10 Encryption used: %11 Compression activated: %12 |
| 0xb0010423 | 11 | SMBDirect load attempt complete. Success: %1 Status code: %2 Service path: %4 Device name: %6 |
| 0xb0010776 | 11 | RDMA listen socket disable override is %1. New value is %2. SrvNetEnableRdmaSupport is %3. Aggregate RDMA enable/policy evaluation is %4. SKU support %5. Action taken %6. |
| 0xb001077a | 11 | The server was unable to perform revocation checks on the client certificate chain. The connection will proceed. Verification Status: %1 Endpoint Name: %3 Transport: %4 Transport Name: %6 Client socket address: %8 |
| 0xb0010bbf | 11 | Access Denied Server certificate mapping name: %2 Client socket address: %4 Connection ID: %14 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server denied access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243808 |
| 0xb0010bc0 | 11 | Access Allowed Server certificate mapping name: %2 Client socket address: %4 Connection ID: %14 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny entries: %10 Allow Entries: %12 Guidance: The server allowed access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243809 |
| 0xb0010bc1 | 11 | An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: %1 Server certificate mapping name: %3 Client socket address: %5 Connection ID: %7 Guidance: For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243709 |
| 0xd000002b | 11 | Error due to active rundown of RDMA for interface %2. %3 |
| 0xd000002c | 11 | Error initilizing the async handle. %4 |
| 0xd000002d | 11 | XsActSrv is not active. |
| 0xd000002e | 11 | Pnp exception. %4 |
| 0xd000002f | 11 | Timeout on comleting pnp operation. %4 |
| 0xd0000030 | 11 | Pnp operation took too long and it was never completed so it must be cancelled. %4 |
| 0xd0000031 | 11 | Error cancelling Pnp opearion. %4 |
| 0xd0000032 | 11 | NsiParameterNotification |
| 0xd0000033 | 11 | NsiAddInstance |
| 0xd0000034 | 11 | NsiDeleteInstance |
| 0xd0000035 | 11 | NsiInitialNotification |
| 0xd0000036 | 11 | MibParameterNotification |
| 0xd0000037 | 11 | MibAddInstance |
| 0xd0000038 | 11 | MibDeleteInstance |
| 0xd0000039 | 11 | MibInitialNotification |
| 0xd000003a | 11 | Registry value defines properties for an FSCTL that has already been defined in another registry value. |
| 0xd000003b | 11 | Registry value specifying FSCTL properties must also specify a non-zero FSCTL code. |
| 0xd000003c | 11 | Registry value specifying FSCTL properties have the wrong format. |
| 0xd000003d | 11 | Error getting unicast ip address table for interface %2. %3 |
| 0xd000003e | 11 | Error finding or adding the interface %2. |
| 0xd000003f | 11 | Error getting Nsi parameters for interface %2. %3 |
| 0xd0000040 | 11 | Error certificate for mapping not found in store. Name: %4 Thumbprint: %6 |
| 0xd0000041 | 11 | Error not enough memory to complete certificate routine Name: %4 Thumbprint: %6 |
| 0xd0000042 | 11 | Error certificate is already registered Name: %4 Thumbprint: %6 |
| 0xd0000043 | 11 | Connection state has not changed. |
| 0xd0000044 | 11 | Connection timed out. |
| 0xd0000045 | 11 | The connection was idle and timed out. |
| 0xd0000046 | 11 | The server is stopping. |
| 0xd0000047 | 11 | The endpoint is closing. |
| 0xd0000048 | 11 | The connection is disconnected. |
| 0xd0000049 | 11 | The idle connection is time out. |
| 0xd000004a | 11 | All channels are closed. |
| 0xd000004b | 11 | Decrypt message error. |
| 0xd000004c | 11 | Irrecoverable error. |
| 0xd000004d | 11 | Unauthenticated connection is closed. |
| 0xd000004e | 11 | Failed to send an interim async response. |
| 0xd000004f | 11 | Insufficient resources. |
| 0xd0000050 | 11 | Decompression error. |
| 0xd0000051 | 11 | SMB transform header are malformed. |
| 0xd0000052 | 11 | Connection/Stream shutdown without error. |
| 0xd0000053 | 11 | Connection/Stream shutdown unknown error. |
| 0xd0000054 | 11 | The event received is not supported. |
| 0xd0000055 | 11 | Invalid Parameter. |
| 0xd0000056 | 11 | The object is not found. |
| 0xd0000057 | 11 | Insufficient resources. |
| 0xd0000058 | 11 | The certificate is not trusted. |
| 0xd0000059 | 11 | The certificate is expired. |
| 0xd000005a | 11 | The certificate is revoked. |
| 0xd000005b | 11 | Mutual authentication failed. |
| 0xd000005c | 11 | The SMB client was denied access to the SMB server during mutual authentication. |
| 0xd000005d | 11 | Server can't create a new connection. |
| 0xd000005e | 11 | Server can't set bidi stream count for the connection. |
| 0xd000005f | 11 | Server can't get the local address. |
| 0xd0000060 | 11 | Server close the connection. |
| 0xd0000061 | 11 | The client certificate validation by Schannel failed. |
| 0xd0000062 | 11 | The client certificate access check failed. |
| 0xd0000063 | 11 | The client certificate access check RPC failed. |
| 0xd0000064 | 11 | QUIC returned an error during the asynchronous client certificate validation. |
| 0xd0000065 | 11 | None |
| 0xd0000066 | 11 | NTLM |
| 0xd0000067 | 11 | Kerberos |
| 0xd0000068 | 11 | PKU2U |
| 0xd0000069 | 11 | Negotiate |
| 0xd000006a | 11 | Session setup |
| 0xd000006b | 11 | Logoff |
| 0xd000006c | 11 | Tree connect |
| 0xd000006d | 11 | Tree disconnect |
| 0xd000006e | 11 | Create |
| 0xd000006f | 11 | Close |
| 0xd0000070 | 11 | Flush |
| 0xd0000071 | 11 | Read |
| 0xd0000072 | 11 | Write |
| 0xd0000073 | 11 | Lock |
| 0xd0000074 | 11 | Ioctl |
| 0xd0000075 | 11 | Cancel |
| 0xd0000076 | 11 | Echo |
| 0xd0000077 | 11 | Query directory |
| 0xd0000078 | 11 | Change notify |
| 0xd0000079 | 11 | Query info |
| 0xd000007a | 11 | Set info |
| 0xd000007b | 11 | Oplock break |
| 0xd000007c | 11 | The server closed the session. |
| 0xd000007d | 11 | The server closed the session due to it idling past the AutoDisconnectTimeout time. |
| 0xd000007e | 11 | The server closed the session due to it being forcibly closed. |
| 0xd000007f | 11 | SRV_PRIMARY_INSTANCE |
| 0xd0000080 | 11 | SRV_CSV_INSTANCE |
| 0xd0000081 | 11 | SRV_SBL_INSTANCE |
| 0xd0000082 | 11 | SRV_SR_INSTANCE |
| 0xd0000083 | 11 | Security Transforms Disabled |
| 0xd0000084 | 11 | Security Transforms Enabled |
| 0xd0000085 | 11 | Security Transforms Enabled (Except For Shares Enabled With Isolated Transport) |
| 0xd0000086 | 11 | SrvNetTransportTypeTdi |
| 0xd0000087 | 11 | SrvNetTransportTypeTcpip |
| 0xd0000088 | 11 | SrvNetTransportTypeRdma |
| 0xd0000089 | 11 | SrvNetTransportTypeVmBus |
| 0xd000008a | 11 | SrvNetTransportTypeQuic |
| 0xd000008b | 11 | N/A |
| 0xd000008c | 11 | Default |
| 0xd000008d | 11 | CSV |
| 0xd000008e | 11 | Default, CSV |
| 0xd000008f | 11 | SBL |
| 0xd0000090 | 11 | Default, SBL |
| 0xd0000091 | 11 | CSV, SBL |
| 0xd0000092 | 11 | Default, CSV, SBL |
| 0xd0000093 | 11 | SR |
| 0xd0000094 | 11 | Default, SR |
| 0xd0000095 | 11 | CSV, SR |
| 0xd0000096 | 11 | Default, CSV, SR |
| 0xd0000097 | 11 | SBL, SR |
| 0xd0000098 | 11 | Default, SBL, SR |
| 0xd0000099 | 11 | CSV, SBL, SR |
| 0xd000009a | 11 | Default, CSV, SBL, SR |
| 0xd000009b | 11 | No |
| 0xd000009c | 11 | Yes |
| 0xd000009d | 11 | TCP |
| 0xd000009e | 11 | UDP |
| 0xd000009f | 11 | The SMB2_GLOBAL_CAP_ENCRYPTION flag is not set in the Capabilities field of the SMB2 NEGOTIATE request. |
| 0xd00000a0 | 11 | The CipherCount field of the SMB2 NEGOTIATE request is 0. |
| 0xf0000001 | 11 | Supports RDMA via SMBDirect |
| 0xf0000002 | 11 | Supports runtime unlinking from SMBDirect |
| 626 entries | ||