Site icon EfmSoft

What does HRESULT 0x87C51009 (UTC_E_EVENTLOG_ENTRY_MALFORMED) mean?

 
Previous Next
UTC_E_FORWARDER_ALREADY_DISABLED UTC_E_DIAGRULES_SCHEMAVERSION_MISMATCH

UTC_E_EVENTLOG_ENTRY_MALFORMED

Interpret the result in context: Event Log XML ingestion

UTC_E_EVENTLOG_ENTRY_MALFORMED (0x87C51009) is a Universal Telemetry Client result from the DiagTrack scenario-definition processing layer. Start by locating the exact scenario-engine boundary that emitted this value. The relevant state is Event Log XML ingestion: UTC received an event representation that could not be parsed as the expected Windows Event Log XML. This identifies a specific UTC/DiagTrack condition, not a general service failure.

Build a minimal evidence set

UTC diagnostic fieldValue
Producing layerDiagTrack scenario-definition processing
Owning state or objectEvent Log XML ingestion
Evidence to collectraw rendered XML, channel/provider/event ID, rendering API, encoding, truncation point and parser error offset
Narrow comparisonexport the same event with wevtutil or Get-WinEvent XML rendering and compare it with the supplied payload
Do not confuse withUTC_E_FILTER_INVALID_COMMAND reports a malformed scenario-filter command, not malformed event XML

Run an A/B check

  1. Associate this result with one request, one scenario version and one service process ID.
  2. Save raw rendered XML, channel/provider/event ID, rendering API, encoding, truncation point and parser error offset and the first lower-level HRESULT if one exists.
  3. Change no policy, provider set or destination except for this test: export the same event with wevtutil or Get-WinEvent XML rendering and compare it with the supplied payload.
  4. Compare the produced artifacts and operational events, not only the top-level return value.

Nearby result: UTC_E_FILTER_INVALID_COMMAND — reports a malformed scenario-filter command, not malformed event XML.

Configuration-generation check

Hash the scenario, rules and referenced profile files used and record the UTC process start time. If files changed after the process loaded them, restart only after preserving the prior generation so the comparison remains auditable.

Safe remediation

Preserve valid Event/System structure, correct encoding or truncation, and retest with one event.

Technical references


Looking for a different code? Search another status or error code.

Exit mobile version