| Previous | Next |
| UTC_E_FILTER_VERSION_MISMATCH | UTC_E_FILTER_INVALID_FUNCTION_PARAMS |
UTC_E_FILTER_INVALID_FUNCTION
Read this as a lifecycle result: filter function lookup
When UTC_E_FILTER_INVALID_FUNCTION (0x87C51050) is returned, the producing layer is scenario filter parser and evaluator. Treat this HRESULT as a state-machine report, not as a generic telemetry outage. The rejected object or state is filter function lookup, and the specific condition is that the expression names a function absent from the supported function table. Keep this first HRESULT even if a later service call reports another error.
UTC filters are typed programs, not plain text searches. Parsing, command validation, name lookup, signature binding and evaluation are distinct phases. Capturing the normalized expression and inferred operand types is essential for a useful diagnosis.
Diagnostic record
| UTC diagnostic field | Value |
|---|---|
| Owning state or object | filter function lookup |
| Producing layer | scenario filter parser and evaluator |
| Do not confuse with | UTC_E_FILTER_FUNCTION_RESTRICTED means the function exists but is disallowed in this context |
| Evidence to collect | function spelling/case, namespace if any, filter version, argument list and client capability |
| Narrow comparison | replace it with a documented function while preserving operand data |
Isolate one changing condition
- Freeze the failing scenario package, caller inputs and UTC service lifetime that produced this result.
- Collect the high-value state: function spelling/case, namespace if any, filter version, argument list and client capability.
- Use a passing control on the same Windows build, then replace it with a documented function while preserving operand data.
- Repeat once after normal teardown to prove the result is not caused by a stale handle or leftover run state.
Nearby result: UTC_E_FILTER_FUNCTION_RESTRICTED — means the function exists but is disallowed in this context.
Typed-filter note
Save the filter after variable substitution and type inference, not only the authoring XML. A visually plausible expression can still fail because the runtime command table, scope or operand types differ from the authoring tool. Test with one synthetic event whose fields and types are known exactly.
Operational response
Correct the generated command or target a client version that supports the needed function.
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for scenario filter parser and evaluator while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis — reference for scenario filter parser and evaluator while interpreting this result.
- Microsoft: Windows Event Log query schema — reference for scenario filter parser and evaluator while interpreting it.
- Microsoft: Querying Windows Event Log
Looking for a different code? Search another status or error code.