| Previous | Next |
| UTC_E_FILTER_VARIABLE_NOT_FOUND | UTC_E_FILTER_VERSION_MISMATCH |
UTC_E_FILTER_FUNCTION_RESTRICTED
Interpret the result in context: filter function context policy
UTC_E_FILTER_FUNCTION_RESTRICTED has the unsigned value 0x87C51048. In UTC it comes from scenario filter parser and evaluator, where filter function context policy owns the decision. Start by locating the exact scenario-engine boundary that emitted this value. The immediate contract failed because the function exists but is forbidden in the current filter context or evaluation phase, so diagnosis should remain at that boundary until a controlled comparison crosses it.
Build a minimal evidence set
| UTC diagnostic field | Value |
|---|---|
| Owning state or object | filter function context policy |
| Producing layer | scenario filter parser and evaluator |
| Do not confuse with | UTC_E_FILTER_INVALID_FUNCTION means the evaluator does not support the named function at all |
| Evidence to collect | function name, command context, scenario/destination, schema version and restriction rule |
| Narrow comparison | call the same function in an allowed context with identical argument values |
Run an A/B check
- Associate this result with one request, one scenario version and one service process ID.
- Save function name, command context, scenario/destination, schema version and restriction rule and the first lower-level HRESULT if one exists.
- Change no policy, provider set or destination except for this test: call the same function in an allowed context with identical argument values.
- Compare the produced artifacts and operational events, not only the top-level return value.
Nearby result: UTC_E_FILTER_INVALID_FUNCTION — means the evaluator does not support the named function at all.
Typed-filter note
Save the filter after variable substitution and type inference, not only the authoring XML. A visually plausible expression can still fail because the runtime command table, scope or operand types differ from the authoring tool. Test with one synthetic event whose fields and types are known exactly.
Safe remediation
Move the computation to an allowed phase or choose a permitted function.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for scenario filter parser and evaluator while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for scenario filter parser and evaluator while interpreting it.
- Microsoft: Windows Event Log query schema
- Microsoft: Querying Windows Event Log
Looking for a different code? Search another status or error code.