Windows 10: Event ID 1 warning & Event ID 2 error

Discus and support Event ID 1 warning & Event ID 2 error in Windows 10 Performance & Maintenance to solve the problem; Hello, After Fall Creators update I'm seeing 1 error and 1 warning in the Event Viewer which I'm not able to resolve. Event ID 1 The backing-file... Discussion in 'Windows 10 Performance & Maintenance' started by eddward, Oct 19, 2017.

  1. eddward Win User

    Event ID 1 warning & Event ID 2 error


    Hello,
    After Fall Creators update I'm seeing 1 error and 1 warning in the Event Viewer which I'm not able to resolve.

    Event ID 1
    The backing-file for the real-time session "DefenderApiLogger" has reached its maximum size. As a result, new events will not be logged to this session until space becomes available. This error is often caused by starting a trace session in real-time mode without having any real-time consumers.
    Code: <System> <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" /> <EventID>1</EventID> <Version>0</Version> <Level>3</Level> <Task>1</Task> <Opcode>10</Opcode> <Keywords>0x8000000000000010</Keywords> <TimeCreated SystemTime="2017-10-19T23:02:23.884086800Z" /> <EventRecordID>26</EventRecordID> <Correlation /> <Execution ProcessID="4" ThreadID="136" /> <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel> <Computer>PC</Computer> <Security UserID="S-1-5-18" /> </System> - <EventData> <Data Name="SessionName">DefenderApiLogger</Data> <Data Name="ErrorCode">3221225864</Data> <Data Name="LoggingMode">411042176</Data> </EventData>[/quote] Event ID 2
    Session "" failed to start with the following error: 0xC0000022
    Code: <System> <Provider Name="Microsoft-Windows-Kernel-EventTracing" Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}" /> <EventID>2</EventID> <Version>0</Version> <Level>2</Level> <Task>2</Task> <Opcode>12</Opcode> <Keywords>0x8000000000000010</Keywords> <TimeCreated SystemTime="2017-10-19T23:02:24.643823700Z" /> <EventRecordID>27</EventRecordID> <Correlation /> <Execution ProcessID="1536" ThreadID="2096" /> <Channel>Microsoft-Windows-Kernel-EventTracing/Admin</Channel> <Computer>PC</Computer> <Security UserID="S-1-5-20" /> </System> - <EventData> <Data Name="SessionName" /> <Data Name="FileName" /> <Data Name="ErrorCode">3221225506</Data> <Data Name="LoggingMode">293609474</Data> </EventData>[/quote] I think it is fixable, but don't know where to start. Does anyone have some idea?
    Thank you in advance.

    :)
     
    eddward, Oct 19, 2017
    #1
  2. CRBW Win User

    Netsh network trace error messages

    How do I look up and resolve netsh network trace error messages?

    I'm having trouble establishing a VPN connection from a Windows 10 client to a remote RRAS server. I see error messages in the client's network trace messages, but I cannot find out what they mean when searching bing or google. These are my error messages:

    netsh ras set tracing * enabled

    Error: Event ID 12000: RRAS-Provider: From !!!!!SDOWRAPPER.LIB!!!!!!!!!!

    Error: Event ID 12000: RRAS-Provider: From !!!!!SDOWRAPPER.LIB!!!!!!!!!!

    Error: Event ID 12000: RRAS-Provider: From !!!!!SDOWRAPPER.LIB!!!!!!!!!!

    Error: Event ID 6002: RRAS-Provider: RasDeviceGetInfo=603,s=296

    Error: Event ID 6002: RRAS-Provider: RasDeviceGetInfo=0,s=296,noParams=3

    Error: Event ID 6002: RRAS-Provider: ConnectionId=4,Destination IP=<RAS-SERVER-IP>

    Error: Event ID 6000: RRAS-Provider: Add new connection with Id 4 @ index 4

    Error: Event ID 6000: RRAS-Provider: Total list of TS Payloads = 1

    Error: Event ID 6002: RRAS-Provider: IsPeerCertValidationForEapDiasabled: RegQueryValueEx for IkeAuthTypeNoServerCert failed with 2

    Error: Event ID 6002: RRAS-Provider: IsCertSubjectNameCheckDisabled failed: RegQueryValueEx for DisableIKENameEkuCheck failed with 2

    Error: Event ID 6000: RRAS-Provider: StartService failed with error: 0

    Error: Event ID 6000: RRAS-Provider: SyncEventEntry object with 4 could NOT be found

    Error: Event ID 6000: RRAS-Provider: SignalEventHandle failed: 1168

    Error: Event ID 6000: RRAS-Provider: Signaling of synchronizing event failed. Error = 1168

    Error: Event ID 14000: RRAS-Provider: Allocating Call context 0x000002CFCBA76D08

    Error: Event ID 14000: RRAS-Provider: CoId={F4D441ED-8FE3-4F4B-BBD8-4EEBBFB27060}:Ignoring revocation failure checks

    Error: Event ID 14000: RRAS-Provider: CoId={F4D441ED-8FE3-4F4B-BBD8-4EEBBFB27060}:GetLinkSpeedForAddr completes with 0 [Tx: 130000000][Rx: 130000000]

    Error: Event ID 16000: RRAS-Provider: EapHostPeerQueryInteractiveUIInputFields dwWinError = 0x80420011

    type:

    eapType: type = 0

    dwVendorId = 0

    dwVendorType = 0

    dwAuthorId = 0

    dwReasonCode = 0x57

    Error: Event ID 16000: RRAS-Provider: FsmInit for protocol = 80fd failed with error 731

    Error: Event ID 16000: RRAS-Provider: Non-LCP packet received when LCP is not opened

    Error: Event ID 16000: RRAS-Provider: Packet being silently discarded

    Error: Event ID 14000: RRAS-Provider: AsyncSstpDeviceIoControl fails with [1168]

    Error: Event ID 14000: RRAS-Provider: CoId={F4D441ED-8FE3-4F4B-BBD8-4EEBBFB27060}:InitiateContextCleanup(0x221)

    Error: Event ID 14000: RRAS-Provider: CoId={F4D441ED-8FE3-4F4B-BBD8-4EEBBFB27060}:ReceiveResponseEntity fails with 995

    Error: Event ID 14000: RRAS-Provider: CoId={F4D441ED-8FE3-4F4B-BBD8-4EEBBFB27060}:InitiateContextCleanup(0x2001)

    Error: Event ID 14000: RRAS-Provider: CoId={F4D441ED-8FE3-4F4B-BBD8-4EEBBFB27060}:InitiateContextCleanup(0x1)

    Error: Event ID 14000: RRAS-Provider: CoId={F4D441ED-8FE3-4F4B-BBD8-4EEBBFB27060}:Freeing up call ctx 0x000002CFCBA76D08

    Error: Event ID 14000: RRAS-Provider: From !!!!!SDOWRAPPER.LIB!!!!!!!!!!
     
  3. MSINFO, MEMORY.DMP and sys info

    I uninstalled Daemon Tools and tried running the game again, PC still force restarted. Here are the new dmp files along with a screenshot of my event viewer which has 2 errors and 1 warning.. errors being a bug check (Event ID 1001) DistributedCOM (Event
    ID 10016) and WHEA-Logger (Event ID 19). I know this isn't a support page for the game...but the fact that its restarting my PC when I attempt to launch leads me to believe that the issue is elsewhere.

    sys


    Event ID 1 warning & Event ID 2 error [​IMG]
     
    DanielGilbertson, Oct 19, 2017
    #3
  4. fdegrove Win User

    Event ID 1 warning & Event ID 2 error

    Hi,

    Are you using TcpView from Sysinternals ? If so, it looks as if it's a bug.
    Further to this look in the registry if you can find this key: Guid="{B675EC37-BDB6-4648-BC92-F3FDC74D3CA2}"
    and see if the log file size is there and if can increase.
    Alternatively, if you do not need the log file for analysis, it can be found under "Users\Username\Appdata\Temp\*.etl and you can delete it.

    Cheers, *Wink
     
    fdegrove, Oct 19, 2017
    #4
  5. Hey,

    I'm also getting event id 2 & event id 360. So far I'm guessing you guys haven't figured anything out?
     
    Black Faith, Oct 19, 2017
    #5
  6. eddward Win User
    No, I'm not aware of using anything like that.
    Anyway, I have solved Event ID 1 by disabling DefenderApiLogger logging in perfmon, but unfortunately Event ID 2 error is still there and I have no clue what is the root cause.
     
    eddward, Oct 19, 2017
    #6
  7. You can disable the logging of event id 2 aswell in event viewer. Though it would be really nice to know what is actually causing it.
     
    Black Faith, Oct 20, 2017
    #7
  8. eddward Win User

    Event ID 1 warning & Event ID 2 error

    Firstly I was trying only to increase the max size for DefenderApiLogger from 100MB to 150MB but it did help only for a while, so I've decided to completely disable logging this stuff, but in the source not in the Event viewer.
    You are right probably I can disable logging of the Event 2, but I would really like to avoid that, since this is not a solution. Moreover I'm not sure if is possible to disable only this particular event or it will affect all Microsoft-Windows-Kernel-EventTracing events.
    There is still a possibilty that it is just a Windows bug which can be solved in the next few cumulative updates.
     
    eddward, Oct 20, 2017
    #8
  9. Well I was lucky enough to not have event id 1 showing up but as you can see from my first post I have event id 2 and 360. I feel the same about disabling the logging of certain events completely cause something actually important might get logged but don't have your hopes high that ms is gonna fix some of these issues asap*cry.
     
    Black Faith, Oct 20, 2017
    #9
  10. eddward Win User
    I managed to find out which proces/service is the root cause. It is svchost.exe - Delivery Optimization service.
    So, what can be wrong with this ?

    edit:
    okay, one more thing... the service is set to automatic (delayed) start and as far as I can see on my second machine it should be running all the time ?
    On first machine it stopped after a while, so maybe this is the culprit for this error ? But why did it happen and how to fix it ?

    edit:
    ok well, it depends on Windows Update advanced settings obviously, but on both machines the setting is the same, so something is not quite right here...
    anyway I disabled this option in Windows update, now it has manual Startup type and the error is still there, but this time I am not able to trace it down with the Process ID from the Event, so dead end.
     
    eddward, Oct 20, 2017
    #10
  11. P83
    p83 Win User
    I also got the "Event ID 1" with the same description after the FCU. How did you solve it?
     
  12. eddward Win User
    Well you can try to increase size of the file or disable logging for this.
    Click Start - write perfmon - enter - on the left tree click on Data Collector Sets - Startup Event Trace Sessions - find DefenderApiLogger. Right click and properties. On the Stop Condition tab you have Maximum size, so you can increase it.
    Or on the Trace Session tab you have checkbox Enabled to disable it.
     
    eddward, Oct 20, 2017
    #12
  13. P83
    p83 Win User

    Event ID 1 warning & Event ID 2 error

    Thanks! *Smile @eddward
     
  14. PacTr Win User
    Found a solution which doesn't require disabling logging.
    ● Start PerfmonData Collector SetsStartup Event Trace Session → right click Defender API Logger → Properties
    ● In the Trace Session tab change Stream Mode to File and Real Time
    ● Select the File tab → under Log Mode tick Circular
    Finally click ok.
    This solved the issue for me.
     
    PacTr, Oct 24, 2017
    #14
  15. P83
    p83 Win User
    I'll try your solution *Smile Thanks!
     
Thema:

Event ID 1 warning & Event ID 2 error

Loading...
  1. Event ID 1 warning & Event ID 2 error - Similar Threads - Event warning Event

  2. Warning Event ID 25 BTHUSB

    in Windows 10 Support
    Warning Event ID 25 BTHUSB: I have a Bluetooth ear piece I've attempted to update the firmware for multiple times. Every time I've tried to, the device fails to update. There are no instruction on how to up the earpiece other than "download the updater software, run it and hit the update button". When I...
  3. BTHUSB warning event ID 34

    in Windows 10 Drivers and Hardware
    BTHUSB warning event ID 34: "The local adapter does not support an important Low Energy controller state to support peripheral mode..." This pops up as a warning in Event Viewer every time the 3148 laptop is booted or awakened from sleep. As a test, "Allow this device to turn off this device to...
  4. Event ID 10031

    in Windows 10 Support
    Event ID 10031: Good point @swarfega. I find Reliability Monitor to be a much quicker way to zero in on stuff I might actually be concerned about. And even then, much of what surfaces -- IE errors of late which is moving me away from IE and more onto Chrome, Firefox and, to some extent, Edge...
  5. Event ID 2: Kernel event tracing

    in Windows 10 Support
    Event ID 2: Kernel event tracing: Umm, today I've been solving all kinds of event errors but this one remained unsolved mostly because I can't find any info about it. It shows in event viewer log on every boot / win restart. I don't know what it is and how does it affects me. I would be grateful if someone...
  6. Event ID 2

    in Windows 10 Performance & Maintenance
    Event ID 2: So I have noticed I have been getting this sometime after Fall Creators Update. Kernal Event Tracing Session "" failed to start with the following error: 0xC0000022 Anybody know what this is? 96363
  7. Event ID 10016

    in Windows 10 Performance & Maintenance
    Event ID 10016: Here is a previous thread about it: Windows 10 Event ID 10010 and 10016 Errors With DistributedCOM - Windows 10 Forums I did run Regedit (as an admin) and did go to that entry in HKEY and did try to change permissions, but I get access denied. What to do now? 100s...
  8. Event id 10016

    in Windows 10 Support
    Event id 10016: I, like many other Win10 users, am getting a lot of DCOM Eventid 10016 events logged. I've seen a number of explanations (which I haven't understood) and several solutions. However, I have not seen a clear description of what requests are failing and what the result of the...
  9. Event ID 1 SpeechRuntime

    in Windows 10 Support
    Event ID 1 SpeechRuntime: So I have this odd quirk the past few days. Sometimes on certain windows apps like Netflix or System settings it will hang till I close out but when I go back into them it acts normal and when I check the event log it gives me this. Audio Orchestrator Power Event: Battery...
  10. Warning Event ID 4101

    in Windows 10 Support
    Warning Event ID 4101: Hi TenForumers. Few days ago I found some strange warnings concerning the display driver (event ID 4101): "Display driver amdkmdap stopped responding and has successfully recovered". After trying this and that with no avail, I noticed these warning were raised when I was...

Users found this page by searching for:

  1. EventID=21022748548

    ,
  2. event 1 warning

    ,
  3. kernel event tracing id 1

    ,
  4. defenderapilogger warning,
  5. The backing-file for the real-time session DefenderApiLogger ,
  6. event id 1 and 2,
  7. iscertsubjectnamecheckdisabled failed,
  8. defenderapilogger event id 1,
  9. DefenderApiLogger error 4,
  10. DefenderApiLogger Error ,
  11. speechruntime 1,
  12. WHEA Error Event Log warning event 2 find more info,
  13. The backing-file for the real-time session DefenderApiLogger has reached its maximum size,
  14. DefenderApiLogger