| Previous | Next |
| UTC_E_FORWARDER_ALREADY_DISABLED | UTC_E_DIAGRULES_SCHEMAVERSION_MISMATCH |
UTC_E_EVENTLOG_ENTRY_MALFORMED
Interpret the result in context: Event Log XML ingestion
UTC_E_EVENTLOG_ENTRY_MALFORMED (0x87C51009) is a Universal Telemetry Client result from the DiagTrack scenario-definition processing layer. Start by locating the exact scenario-engine boundary that emitted this value. The relevant state is Event Log XML ingestion: UTC received an event representation that could not be parsed as the expected Windows Event Log XML. This identifies a specific UTC/DiagTrack condition, not a general service failure.
Build a minimal evidence set
| UTC diagnostic field | Value |
|---|---|
| Producing layer | DiagTrack scenario-definition processing |
| Owning state or object | Event Log XML ingestion |
| Evidence to collect | raw rendered XML, channel/provider/event ID, rendering API, encoding, truncation point and parser error offset |
| Narrow comparison | export the same event with wevtutil or Get-WinEvent XML rendering and compare it with the supplied payload |
| Do not confuse with | UTC_E_FILTER_INVALID_COMMAND reports a malformed scenario-filter command, not malformed event XML |
Run an A/B check
- Associate this result with one request, one scenario version and one service process ID.
- Save raw rendered XML, channel/provider/event ID, rendering API, encoding, truncation point and parser error offset and the first lower-level HRESULT if one exists.
- Change no policy, provider set or destination except for this test: export the same event with wevtutil or Get-WinEvent XML rendering and compare it with the supplied payload.
- Compare the produced artifacts and operational events, not only the top-level return value.
Nearby result: UTC_E_FILTER_INVALID_COMMAND — reports a malformed scenario-filter command, not malformed event XML.
Configuration-generation check
Hash the scenario, rules and referenced profile files used and record the UTC process start time. If files changed after the process loaded them, restart only after preserving the prior generation so the comparison remains auditable.
Safe remediation
Preserve valid Event/System structure, correct encoding or truncation, and retest with one event.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for DiagTrack scenario-definition processing while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for DiagTrack scenario-definition processing while interpreting this result.
- Microsoft: UniversalTelemetryClient operational-log guidance — reference for DiagTrack scenario-definition processing while interpreting it.
- Microsoft: Windows Event Log query schema
Looking for a different code? Search another status or error code.