Microsoft-Windows-FailoverClustering-CsvFs-Diagnostic
110 events across 3 channels
Event ID 16 —
Description
Activity Transfer.
Event ID 16 — Activity Transfer.
Description
Activity Transfer.
Message #
Event ID 256 —
Description
Openning file .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
Volume Pointer | — |
VolumeId GUID | — |
FileObject Pointer | — |
RelativeFileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
DesiredAccess HexInt32 | — Process access rights reference |
Options HexInt32 | — |
SharedAccess HexInt32 | — |
AttributeFlags HexInt32 | — |
Event ID 256 — Openning file FileName.
Description
Openning file FileName.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
Volume Pointer | — |
VolumeId GUID | — |
FileObject Pointer | — |
RelativeFileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
DesiredAccess HexInt32 | — Process access rights reference |
Options HexInt32 | — |
SharedAccess HexInt32 | — |
AttributeFlags HexInt32 | — |
Event ID 512 —
Description
Closing file object .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Event ID 512 — Closing file object FileName.
Event ID 768 —
Description
Cleaning file object .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Event ID 768 — Cleaning file object FileName.
Event ID 848 —
Description
All file objects for the stream Scb are invalidated. Reason: 'Reason'.
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
Condition HexInt32 | — |
Reason HexInt32 | — |
Vcb Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 848 — All file objects for the stream Scb are invalidated.
Description
All file objects for the stream Scb are invalidated. Reason: 'Reason'.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
Condition HexInt32 | — |
Reason HexInt32 | — |
Vcb Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 864 —
Description
All file objects for the stream Scb of file id FileIdHi.FileId are invalidated. Reason: 'Reason'.
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
Scb Pointer | — |
Condition HexInt32 | — |
Reason HexInt32 | — |
Volume Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 864 — All file objects for the stream Scb of file id FileIdHi.
Description
All file objects for the stream Scb of file id FileIdHi.FileId are invalidated. Reason: 'Reason'.
Message #
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
Scb Pointer | — |
Condition HexInt32 | — |
Reason HexInt32 | — |
Volume Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 885 —
Description
File handle FileObject for the stream Ccb is invalidated. Reason: 'Reason'.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Flags HexInt32 | — |
Reason HexInt32 | — |
Vcb Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 885 — File handle FileObject for the stream Ccb is invalidated.
Description
File handle FileObject for the stream Ccb is invalidated. Reason: 'Reason'.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Flags HexInt32 | — |
Reason HexInt32 | — |
Vcb Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 896 —
Description
File handle FileObject for the stream Scb file id .FileIdHi.FileId is invalidated. Reason: 'Reason'. File name: 'FileName'.
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Flags HexInt32 | — |
Reason HexInt32 | — |
Volume Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 896 — File handle FileObject for the stream Scb file id .
Description
File handle FileObject for the stream Scb file id .FileIdHi.FileId is invalidated. Reason: 'Reason'. File name: 'FileName'.
Message #
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Flags HexInt32 | — |
Reason HexInt32 | — |
Volume Pointer | — |
VolumeId GUID | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1024 —
Description
Query Volume Information completed with status .
Fields #
| Name | Description |
|---|---|
Vcb Pointer | — |
BytesPerSector HexInt64 | — |
BytesPerCluster HexInt64 | — |
BytesPerFileRecordSegment HexInt64 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 1024 — Query Volume Information completed with status status.
Description
Query Volume Information completed with status status.
Message #
Fields #
| Name | Description |
|---|---|
Vcb Pointer | — |
BytesPerSector HexInt64 | — |
BytesPerCluster HexInt64 | — |
BytesPerFileRecordSegment HexInt64 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 1280 —
Description
Down-level File Object is opened with status .
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
CreateDisposition HexInt32 | — |
DesiredAccess HexInt32 | — Process access rights reference |
SharedAccess HexInt32 | — |
CreateFlags HexInt32 | — |
AttributeFlags HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1280 — Down-level File Object FileName is opened with status Status.
Description
Down-level File Object FileName is opened with status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
CreateDisposition HexInt32 | — |
DesiredAccess HexInt32 | — Process access rights reference |
SharedAccess HexInt32 | — |
CreateFlags HexInt32 | — |
AttributeFlags HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1536 —
Description
Down-level File Object is closed.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Event ID 1536 — Down-level File Object FileName is closed.
Event ID 1792 —
Description
Down-level File Object is released.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Event ID 1792 — Down-level File Object FileName is released.
Event ID 2048 —
Description
Paging File Object is opened with status .
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
CreateDisposition HexInt32 | — |
DesiredAccess HexInt32 | — Process access rights reference |
SharedAccess HexInt32 | — |
CreateFlags HexInt32 | — |
AttributeFlags HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 2048 — Paging File Object FileNameLength is opened with status AttributeFlags.
Description
Paging File Object FileNameLength is opened with status AttributeFlags.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
CreateDisposition HexInt32 | — |
DesiredAccess HexInt32 | — Process access rights reference |
SharedAccess HexInt32 | — |
CreateFlags HexInt32 | — |
AttributeFlags HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 2304 —
Description
Paging File Object is closed.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Event ID 2304 — Paging File Object FileNameLength is closed.
Event ID 4096 —
Description
Paging File Object is released.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Event ID 4096 — Paging File Object FileNameLength is released.
Event ID 6144 —
Description
Received Byte Range Lock Request . At ; Length ; Key ; Fags .
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
Irp Pointer | — |
MinorFunction HexInt32 | — |
Flags HexInt32 | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
FailImmediately Boolean | — |
Exclusive Boolean | — |
Event ID 6144 — Received Byte Range Lock Request MinorFunction.
Description
Received Byte Range Lock Request MinorFunction. At Offset; Length Length; Key Key; Fags Flags.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
Irp Pointer | — |
MinorFunction HexInt32 | — |
Flags HexInt32 | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
FailImmediately Boolean | — |
Exclusive Boolean | — |
Event ID 6400 —
Description
Completed Byte Range Lock Request . At ; Length ; Key ; Fags .
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
Irp Pointer | — |
MinorFunction HexInt32 | — |
Flags HexInt32 | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
FailImmediately Boolean | — |
Exclusive Boolean | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 6400 — Completed Byte Range Lock Request MinorFunction.
Description
Completed Byte Range Lock Request MinorFunction. At Offset; Length Length; Key Key; Fags Flags.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
Irp Pointer | — |
MinorFunction HexInt32 | — |
Flags HexInt32 | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
FailImmediately Boolean | — |
Exclusive Boolean | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 8192 —
Description
Removed Lock. At ; Length ; Key ; Exclusive .
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Irp Pointer | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
Exclusive Boolean | — |
Context Pointer | — |
Event ID 8192 — Removed Lock.
Event ID 8208 —
Description
Cleanup Locks. Status . Downlevel status .
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Process Pointer | — |
Status HexInt32 | — NTSTATUS reference |
DownLevelStatus HexInt32 | — |
Event ID 8208 — Cleanup Locks.
Description
Cleanup Locks. Status Status. Downlevel status DownLevelStatus.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Process Pointer | — |
Status HexInt32 | — NTSTATUS reference |
DownLevelStatus HexInt32 | — |
Event ID 8224 —
Description
Resume Lock. At ; Length ; Key ; Exclusive . Status .
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
Exclusive Boolean | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 8224 — Resume Lock.
Description
Resume Lock. At Offset; Length Length; Key Key; Exclusive Exclusive. Status Status.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
Exclusive Boolean | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 8272 —
Description
Resuming oplock to level completed with status .
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
OplockLevel HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 8272 — Resuming oplock to level OplockLevel completed with status Status.
Description
Resuming oplock to level OplockLevel completed with status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Scb Pointer | — |
OplockLevel HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 8448 —
Description
Enqueuing Single Client Notify. For File ; Oplock Level is ; Ignore Current Conditions .
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
FullPathLength UInt16 | — |
FullPath UnicodeString | — |
OplockLevel HexInt32 | — |
IgnoreCurrentConditions Boolean | — |
Event ID 8448 — Enqueuing Single Client Notify.
Description
Enqueuing Single Client Notify. For File FullPathLength; Oplock Level is OplockLevel; Ignore Current Conditions IgnoreCurrentConditions.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
FullPathLength UInt16 | — |
FullPath UnicodeString | — |
OplockLevel HexInt32 | — |
IgnoreCurrentConditions Boolean | — |
Event ID 8464 —
Description
Single Client Notify Completion. For File ; Oplock Level is ; Status ; Is Event Completion .
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
FullPathLength UInt16 | — |
FullPath UnicodeString | — |
OplockLevel HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
IsEventCompletion Boolean | — |
Event ID 8464 — Single Client Notify Completion.
Description
Single Client Notify Completion. For File FullPath; Oplock Level is OplockLevel; Status Status; Is Event Completion IsEventCompletion.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | — |
Scb Pointer | — |
FullPathLength UInt16 | — |
FullPath UnicodeString | — |
OplockLevel HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
IsEventCompletion Boolean | — |
Event ID 8704 —
Description
Volume transitioning from to SetDownlevel. Local ; Flags ; CountersName ; Volume target path ; File System target path .
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
CurrentState UInt32 | — |
IsLocal Boolean | — |
Flags HexInt32 | — |
CountersName UnicodeString | — |
VolumeTargetPath UnicodeString | — |
FsTargetPath UnicodeString | — |
EnableCOW Boolean | — |
EnableDirectIo Boolean | — |
ForceWriteThrough Int32 | — |
TargetNodeId Int32 | — |
DcmSequenceId UnicodeString | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceLastStateTransition UInt64 | — |
Lifetime UInt64 | — |
Event ID 8704 — Volume VolumeId transitioning from CurrentState to SetDownlevel.
Description
Volume VolumeId transitioning from CurrentState to SetDownlevel. Local IsLocal; Flags Flags; CountersName CountersName; Volume target path VolumeTargetPath; File System target path FsTargetPath.
Message #
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
CurrentState UInt32 | — |
IsLocal Boolean | — |
Flags HexInt32 | — |
CountersName UnicodeString | — |
VolumeTargetPath UnicodeString | — |
FsTargetPath UnicodeString | — |
EnableCOW Boolean | — |
EnableDirectIo Boolean | — |
ForceWriteThrough Int32 | — |
TargetNodeId Int32 | — |
DcmSequenceId UnicodeString | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceLastStateTransition UInt64 | — |
Lifetime UInt64 | — |
Event ID 8960 —
Description
Volume transitioning from to .
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
CurrentState UInt32 | — |
NewState UInt32 | — |
DcmSequenceId UnicodeString | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceLastStateTransition UInt64 | — |
Lifetime UInt64 | — |
Event ID 8960 — Volume VolumeId transitioning from CurrentState to NewState.
Event ID 9216 —
Description
Volume moved to state . Reason ; Status .
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
State UInt32 | — |
Source UInt32 | — |
Status HexInt32 | — NTSTATUS reference |
DcmSequenceId UnicodeString | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceStateTransitionStart UInt64 | — |
Lifetime UInt64 | — |
InvalidationReason UInt32 | — |
Event ID 9216 — Volume VolumeId moved to state State.
Description
Volume VolumeId moved to state State. Reason Source; Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
State UInt32 | — |
Source UInt32 | — |
Status HexInt32 | — NTSTATUS reference |
DcmSequenceId UnicodeString | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceStateTransitionStart UInt64 | — |
Lifetime UInt64 | — |
InvalidationReason UInt32 | — |
Event ID 9296 —
Description
Volume is autopaused. Status . Source: .
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
CountersName UnicodeString | — |
FromDirectIo Boolean | — |
Irp Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Source UInt32 | — |
Parameter1 HexInt64 | — |
Parameter2 HexInt64 | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceLastStateTransition UInt64 | — |
Lifetime UInt64 | — |
Event ID 9296 — Volume VolumeId is autopaused.
Description
Volume VolumeId is autopaused. Status Status. Source: Source.
Message #
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
CountersName UnicodeString | — |
FromDirectIo Boolean | — |
Irp Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Source UInt32 | — |
Parameter1 HexInt64 | — |
Parameter2 HexInt64 | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceLastStateTransition UInt64 | — |
Lifetime UInt64 | — |
Event ID 9312 —
Description
Volume was renamed. New name .
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
CountersName UnicodeString | — |
CurrentState UInt32 | — |
DcmSequenceId UnicodeString | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceLastStateTransition UInt64 | — |
Lifetime UInt64 | — |
Event ID 9312 — Volume was renamed.
Event ID 9328 —
Description
IOs timed out on the volume .
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
Count UInt64 | — |
LastUptime UInt64 | — |
CurrentDowntime UInt64 | — |
TimeSinceStateTransitionStart UInt64 | — |
Lifetime UInt64 | — |
Event ID 9328 — Count IOs timed out on the volume VolumeId.
Event ID 9472 —
Description
Start IO on (). Major Code . Minor Code .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
FileObject Pointer | — |
Vcb Pointer | — |
Scb Pointer | — |
Ccb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
IrpFlags HexInt32 | — |
IrpContextFlags HexInt32 | — |
MajorFunction HexInt32 | — |
MinorFunction HexInt32 | — |
IrpSlFlags HexInt32 | — |
Control HexInt32 | — |
Parameter1 HexInt64 | — |
Parameter2 HexInt64 | — |
Parameter3 HexInt64 | — |
Parameter4 HexInt64 | — |
IrpContextFlagsUpper HexInt32 | — |
Event ID 9472 — Start IO Irp on FileObject (FileName).
Description
Start IO Irp on FileObject (FileName). Major Code MajorFunction. Minor Code MinorFunction.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
FileObject Pointer | — |
Vcb Pointer | — |
Scb Pointer | — |
Ccb Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
IrpFlags HexInt32 | — |
IrpContextFlags HexInt32 | — |
MajorFunction HexInt32 | — |
MinorFunction HexInt32 | — |
IrpSlFlags HexInt32 | — |
Control HexInt32 | — |
Parameter1 HexInt64 | — |
Parameter2 HexInt64 | — |
Parameter3 HexInt64 | — |
Parameter4 HexInt64 | — |
IrpContextFlagsUpper HexInt32 | — |
Event ID 9728 —
Description
Completed IO . Status . Information .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
Event ID 9728 — Completed IO Irp.
Description
Completed IO Irp. Status Status. Information Information.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
Event ID 9984 —
Description
Posted IO .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Event ID 9984 — Posted IO Irp.
Event ID 10240 —
Description
Continue IO .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Event ID 10240 — Continue IO Irp.
Event ID 10496 —
Description
Pause IO . Status . Information .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
IrpContextFlags HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
IrpContextFlagsUpper HexInt32 | — |
Event ID 10496 — Pause IO Irp.
Description
Pause IO Irp. Status IrpContextFlags. Information Status.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
IrpContextFlags HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
IrpContextFlagsUpper HexInt32 | — |
Event ID 12288 —
Description
Resume IO .
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Event ID 12288 — Resume IO Irp.
Event ID 12320 —
Description
Direct IO . Status . Information . Duration 100s nanoseconds.
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
Duration HexInt64 | — |
RedirectionReason HexInt32 | — |
Event ID 12320 — Direct IO Irp.
Description
Direct IO Irp. Status Status. Information Information. Duration Duration 100s nanoseconds.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
Duration HexInt64 | — |
RedirectionReason HexInt32 | — |
Event ID 12336 —
Description
Redirect IO . Status . Information . Duration 100s nanoseconds.
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
Duration HexInt64 | — |
RedirectionReason HexInt32 | — |
Event ID 12336 — Redirect IO Irp.
Description
Redirect IO Irp. Status Status. Information Information. Duration Duration 100s nanoseconds.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | — |
IrpContext Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Information HexInt64 | — |
Duration HexInt64 | — |
RedirectionReason HexInt32 | — |
Event ID 12368 —
Description
Current Node Id .
Fields #
| Name | Description |
|---|---|
NodeId Int32 | — |
ReportCsvFs Boolean | — |
Event ID 12368 — Current Node Id NodeId.
Event ID 12544 —
Description
Volume , .
Fields #
| Name | Description |
|---|---|
Volume Pointer | — |
VolumeId GUID | — |
VpbFlags Int32 | — |
State UInt32 | — |
CountersName UnicodeString | — |
VolumeTargetPath UnicodeString | — |
FsTargetPath UnicodeString | — |
EnableCOW Boolean | — |
EnableDirectIo Boolean | — |
ForceWriteThrough Int32 | — |
TargetNodeId Int32 | — |
Event ID 12544 — Volume VolumeId, CountersName.
Event ID 12800 —
Fields #
| Name | Description |
|---|---|
Vcb Pointer | — |
Scb Pointer | — |
ScbState HexInt32 | — |
ScbCondition HexInt32 | — |
ScbConditionStatus HexInt32 | — |
ScbDownlevelOplockLevel HexInt32 | — |
FileId HexInt64 | — |
Ccb Pointer | — |
CcbFlags HexInt32 | — |
ShadowFileObject Pointer | — |
RealFileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
CreateDisposition HexInt32 | — |
DesiredAccess HexInt32 | — Process access rights reference |
SharedAccess HexInt32 | — |
CreateFlags HexInt32 | — |
AttributeFlags HexInt32 | — |
FileIdHi HexInt64 | — |
Event ID 12800 — File FileName.
Message #
Fields #
| Name | Description |
|---|---|
Vcb Pointer | — |
Scb Pointer | — |
ScbState HexInt32 | — |
ScbCondition HexInt32 | — |
ScbConditionStatus HexInt32 | — |
ScbDownlevelOplockLevel HexInt32 | — |
FileId HexInt64 | — |
Ccb Pointer | — |
CcbFlags HexInt32 | — |
ShadowFileObject Pointer | — |
RealFileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
CreateDisposition HexInt32 | — |
DesiredAccess HexInt32 | — Process access rights reference |
SharedAccess HexInt32 | — |
CreateFlags HexInt32 | — |
AttributeFlags HexInt32 | — |
FileIdHi HexInt64 | — |
Event ID 13056 —
Description
Lock. At ; Length ; Key ; Exclusive .
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
File Pointer | — |
Process Pointer | — |
Offset HexInt64 | — |
Length HexInt64 | — |
Key HexInt32 | — |
Exclusive Boolean | — |
Context Pointer | — |
Event ID 13056 — Lock.
Event ID 16384 —
Description
Tunnel operation . Result .
Fields #
| Name | Description |
|---|---|
TunnelOperationCode HexInt32 | — |
TunnelActivityId HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 16384 — Tunnel operation TunnelOperationCode.
Description
Tunnel operation TunnelOperationCode. Result status.
Message #
Fields #
| Name | Description |
|---|---|
TunnelOperationCode HexInt32 | — |
TunnelActivityId HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 20480 —
Description
Stream was flushed and purged from offset , length . Result .
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
FileOffset HexInt64 | — |
Length HexInt32 | — |
Flags HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 20480 — Stream was flushed and purged from offset FileOffset, length Length.
Description
Stream was flushed and purged from offset FileOffset, length Length. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
FileOffset HexInt64 | — |
Length HexInt32 | — |
Flags HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 24576 —
Description
Stream was flushed from offset , length . Result .
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
FileOffset HexInt64 | — |
Length HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 24576 — Stream was flushed from offset FileOffset, length Length.
Description
Stream was flushed from offset FileOffset, length Length. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
FileOffset HexInt64 | — |
Length HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 28672 —
Description
Stream was purged from offset , length . Result .
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
FileOffset HexInt64 | — |
Length HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 28672 — Stream was purged from offset FileOffset, length Length.
Description
Stream was purged from offset FileOffset, length Length. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | — |
FileOffset HexInt64 | — |
Length HexInt32 | — |
status HexInt32 | — NTSTATUS reference |
Event ID 32768 —
Description
Volume was purged. Result .
Fields #
| Name | Description |
|---|---|
Vcb Pointer | — |
status HexInt32 | — NTSTATUS reference |
Event ID 32768 — Volume was purged.
Description
Volume was purged. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Vcb Pointer | — |
status HexInt32 | — NTSTATUS reference |
Event ID 36864 —
Description
Bookmark: .
Fields #
| Name | Description |
|---|---|
Vcb Pointer | — |
Scb Pointer | — |
FileId HexInt64 | — |
Ccb Pointer | — |
ShadowFileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
BookmarkLength UInt16 | — |
Bookmark UnicodeString | — |
FileIdHi HexInt64 | — |
Event ID 36864 — Bookmark: Bookmark.
Event ID 40960 —
Description
Driver loaded.
Fields #
| Name | Description |
|---|---|
MaxLookAsideDepth UInt64 | — |
CpuCount UInt64 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 40960 — Driver loaded.
Description
Driver loaded.
Message #
Fields #
| Name | Description |
|---|---|
MaxLookAsideDepth UInt64 | — |
CpuCount UInt64 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 45056 —
Description
Cluster service connected.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
ProcessId Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 45056 — Cluster service connected.
Description
Cluster service connected.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
ProcessId Pointer | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 49152 —
Description
Cluster service disconnected.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
ProcessId Pointer | — |
Event ID 49152 — Cluster service disconnected.
Event ID 53248 —
Description
Data section created.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Scb Pointer | — |
Ccb Pointer | — |
Operation UInt16 | — Known values
|
SyncType UInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 53248 — Data section created.
Description
Data section created.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Scb Pointer | — |
Ccb Pointer | — |
Operation UInt16 | — Known values
|
SyncType UInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 57344 —
Description
Shared Cahce Map Initialized.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Scb Pointer | — |
Ccb Pointer | — |
Event ID 57344 — Shared Cahce Map Initialized.
Event ID 61440 —
Description
Shared Cahce Map Uninitialized.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
FileNameLength UInt16 | — |
FileName UnicodeString | — |
Scb Pointer | — |
Ccb Pointer | — |
TruncateSize HexInt64 | — |
HasEvent Boolean | — |
Result Boolean | — |
Event ID 61440 — Shared Cahce Map Uninitialized.
Event ID 61696 —
Description
Capture full payload.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Fcb Pointer | — |
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
StreamId HexInt64 | — |
OplockLevel HexInt32 | — |
Flags HexInt32 | — |
Offset HexInt64 | — |
Length HexInt32 | — |
Data Binary | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 61696 — Capture full payload.
Description
Capture full payload.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Fcb Pointer | — |
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
StreamId HexInt64 | — |
OplockLevel HexInt32 | — |
Flags HexInt32 | — |
Offset HexInt64 | — |
Length HexInt32 | — |
Data Binary | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 61952 —
Description
Capture payload segment.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Fcb Pointer | — |
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
StreamId HexInt64 | — |
OplockLevel HexInt32 | — |
Flags HexInt32 | — |
Offset HexInt64 | — |
Length HexInt32 | — |
FragmentOffset HexInt64 | — |
FragmentLength HexInt32 | — |
Data Binary | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 61952 — Capture payload segment.
Description
Capture payload segment.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | — |
Ccb Pointer | — |
Scb Pointer | — |
Fcb Pointer | — |
FileId HexInt64 | — |
FileIdHi HexInt64 | — |
StreamId HexInt64 | — |
OplockLevel HexInt32 | — |
Flags HexInt32 | — |
Offset HexInt64 | — |
Length HexInt32 | — |
FragmentOffset HexInt64 | — |
FragmentLength HexInt32 | — |
Data Binary | — |
Status HexInt32 | — NTSTATUS reference |