36887
A fatal TLS alert was received from the remote endpoint
- Log: System
- Source: Schannel
- TLS & certificates
- Info
What it means
A TLS connection failed and the other side sent an alert code, for example 40 (handshake failure) or 70 (protocol version).
Why it matters
Usually noise, but bursts after disabling old TLS versions show which systems still need them.
What to do
- Look up the alert code.
- Find the remote system and update its TLS settings.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'System'; Id = 36887
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us