远程桌面卡死,查看日志报错UserID:S-1-5-18
远程桌面卡死,查看日志报错UserID:S-1-5-18
-System__-__System|||-
Provider
[ Name]
Microsoft-Windows-TerminalServices-LocalSessionManager
[ Guid]
{5d896912-022d-40aa-a3a8-4fa5515c76d7}|-|Provider||||[ Name]|Microsoft-Windows-TerminalServices-LocalSessionManager||||[ Guid]|{5d896912-022d-40aa-a3a8-4fa5515c76d7}|
| -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- |
|||-Provider - Provider [ Name]Microsoft-Windows-TerminalServices-LocalSessionManager [ Name] Microsoft-Windows-TerminalServices-LocalSessionManager [ Guid]{5d896912-022d-40aa-a3a8-4fa5515c76d7} [ Guid] {5d896912-022d-40aa-a3a8-4fa5515c76d7}|
|||EventID
25||EventID|25|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||EventID25 EventID 25|
|||Version
0||Version|0|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||Version0 Version 0|
|||Level
4||Level|4|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||Level4 Level 4|
|||Task
0||Task|0|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||Task0 Task 0|
|||Opcode
0||Opcode|0|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||Opcode0 Opcode 0|
|||Keywords
0x1000000000000000||Keywords|0x1000000000000000|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||Keywords0x1000000000000000 Keywords 0x1000000000000000|
|||-
TimeCreated
[ SystemTime]
2025-09-06T10:55:31.579540600Z|-|TimeCreated||||[ SystemTime]|2025-09-06T10:55:31.579540600Z|
| -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- |
|||-TimeCreated - TimeCreated [ SystemTime]2025-09-06T10:55:31.579540600Z [ SystemTime] 2025-09-06T10:55:31.579540600Z|
|||EventRecordID
1931||EventRecordID|1931|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||EventRecordID1931 EventRecordID 1931|
|||-
Correlation
[ ActivityID]
{f4202b97-d3dc-4b4e-9e86-404904770000}|-|Correlation||||[ ActivityID]|{f4202b97-d3dc-4b4e-9e86-404904770000}|
| -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- |
|||-Correlation - Correlation [ ActivityID]{f4202b97-d3dc-4b4e-9e86-404904770000} [ ActivityID] {f4202b97-d3dc-4b4e-9e86-404904770000}|
|||-
Execution
[ ProcessID]
1248
[ ThreadID]
17048|-|Execution||||[ ProcessID]|1248||||[ ThreadID]|17048|
| -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- |
|||-Execution - Execution [ ProcessID]1248 [ ProcessID] 1248 [ ThreadID]17048 [ ThreadID] 17048|
|||Channel
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational||Channel|Microsoft-Windows-TerminalServices-LocalSessionManager/Operational|
| -------- | -------- | -------- | -------- | -------- | -------- |
|||ChannelMicrosoft-Windows-TerminalServices-LocalSessionManager/Operational Channel Microsoft-Windows-TerminalServices-LocalSessionManager/Operational|
|||-
Security
[ UserID]
S-1-5-18|-|Security||||[ UserID]|S-1-5-18|
| -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- | -------- |
|||-Security - Security [ UserID]S-1-5-18 [ UserID] S-1-5-18|