Where are Windows 11 first-boot OOBE errors logged when Event Viewer shows nothing
0 reputation · 29 Sept 2026, 04:54 UTC
0 reputation · 29 Sept 2026, 04:54 UTC
Diagnosing a failed Windows 11 deployment relies on a set of documented setup and servicing logs. The Panther folder contains setupact.log and setupdev.log with phase-level success and failure codes. Event Viewer Windows Logs System and Application includes entries from Microsoft-Windows-Setup, DISM and Client-Side Extension. Component servicing outcomes are captured in %WINDIR%\Logs\CBS\CBS.log.
The logging coverage during first-boot OOBE is unclear. Findings indicate that certain transient errors in the OOBE phase are recorded only in the hidden file %WINDIR%\Panther\UnattendGC\setupact.log and are not surfaced in the standard Event Viewer. Log locations can differ with non-system drive installs or Panther redirection via unattend.xml, and error code meanings can change between Windows 11 releases.
Does Microsoft document that OOBE-phase transient errors are intentionally omitted from Event Viewer? Which Windows 11 builds consistently write OOBE errors to Panther\UnattendGC\setupact.log versus the main Panther log? When should administrators inspect UnattendGC logs in addition to standard Event Viewer and CBS logs?
29775 reputation · 29 Sept 2026, 08:14 UTC
During first-boot OOBE, certain transient errors bypass Event Viewer entirely. This happens because the setup process runs in a specialized boot environment where the Event Log service may not be fully initialized. Microsoft does not publicly document this intentional omission, but it's a well-known behavior in deployment engineering circles.
Start with the standard deployment logs, then check the often-overlooked UnattendGC subfolder:
The UnattendGC\setupact.log file specifically captures errors during the final OOBE configuration pass, including failures in user account creation, network provisioning, and answer file processing.
Log behavior varies between Windows 11 builds. In 22H2 and 23H2, network-based provisioning (NPE) timeouts and user creation failures are most likely to appear only in UnattendGC\setupact.log. If you're using a non-system drive installation or have customized logging via unattend.xml, paths may be redirected. Always verify the UnattendGC directory exists after a failed OOBE attempt.
%SystemRoot%\Panther\UnattendGC\setupact.logsetupact.log and UnattendGC\setupact.log to identify the exact failure pointMicrosoft-Windows-Setup source with Event ID in the 0000 series in Event ViewerTransient errors during network provisioning or user account creation may not generate Event Log entries if the process crashes before flushing buffers. Error code meanings can shift between Windows 11 releases, so focus on the log context rather than specific codes. If you're not seeing any UnattendGC folder, the OOBE may have failed earlier than expected, or the system may have rebooted successfully past that phase.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.