Skip to main content
Skip table of contents

MS Windows Event Logging XML - WMI

Device Details

Device NameMS Windows Event Logging XML - WMI   
Device TypeN/A
Supported Model Name/NumberN/A
Supported Software VersionN/A
Collection MethodMS Windows Event 
Configurable Log OutputN/A
Log Source TypeMS Windows Event Logging XML - WMI
Log Processing PolicyLogRhythm Default V 2.0
Additional Information

Supported Log Messages

(List of LR tags used to parse the log information for each message type)


Product Version

Supported Schema Fields

Catch-AllN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>
EVID 1 : Event Sequence StartN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <process>, <sname>, <login>, <processid>
EVID 2 : Events That Make Up OperationN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <process>
EVID 3 : Event Sequence EndedN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <processid>
EVID 19 : Event Filters RegisteredN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <process>, <processid>
EVID 20 : Event Consumers RegisteredN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <process>, <processid>
EVID 21 : Event Subscription RegisteredN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>
EVID 50 : Generic Error EventN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>
EVID 100 : Degradation has been DetectedN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <subject>, <object>
EVID 101 : Task Scheduler FailedN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <object>, <reason>
EVID 5857 : Operation StartedN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <responsecode>, <process>, <processid>
EVID 5858 : Client FailureN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <sname>, <domainorigin>, <login>, <processid>, <process>, <responsecode>, <reason>
EVID 5859 : Ess StartedN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <domainorigin>, <login>, <processid>, <reason>
EVID 5860 : Temporary Ess StartedN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <domainorigin>, <login>, <processid>, <sname>, <reason>
EVID 5861 : Ess Consumer BindingN/A<vmid>, <severity>, <vendorinfo>, <result>, <dname>, <reason>

Revision History

KB Version

Log Type

Change Type


KB 7.1.XXX.XSyslog - MS Windows Event Logging XML - WMI  New Device DocumentationN/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.