Microsoft-Windows-HAL
20 events across 2 channels
Event ID 1 — Initialization of the High Precision Event Timer failed due to a BIOS configuration problem.
Message
Fields
| Name | Description |
|---|---|
Initialization_status | — |
Status | — |
Event ID 2 — Initialization of the High Precision Event Timer failed due to unsupported hardware.
Message
Fields
| Name | Description |
|---|---|
Initialization_status | — |
Status | — |
Event ID 3 — Initialization of the High Precision Event Timer failed due to an interrupt configuration problem.
Message
Fields
| Name | Description |
|---|---|
Initialization_status | — |
Status | — |
Event ID 4 — Due to an unexpected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 5 — Due to an expected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 7 — The processor cycle counter on processor %2 has been probed by processor %1.
Message
Fields
| Name | Description |
|---|---|
LeadProcessor | — |
TargetProcessor | — |
Delta | — |
NopCycles | — |
Event ID 8 — The processor's cycle counters have been successfully synchronized from processor %1 within acceptable operating thresholds.
Message
Fields
| Name | Description |
|---|---|
LeadProcessor | — |
MaximumPositiveDeltaProcessor | — |
MaximumPositiveDelta | — |
MaximumNegativeDelta | — |
Microseconds | — |
Event ID 9 — The processor cycle counter on processor %2 was synchronized against processor %1 using an adjustment of %4 cycles on attempt %5.
Message
Fields
| Name | Description |
|---|---|
SourceProcessor | — |
TargetProcessor | — |
Delta | — |
Bias | — |
Wave | — |
Event ID 10 — The synchronization of the processor's cycle counters was not able to synchronize the processors within acceptable operating thresholds.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 11 — The High Precision Event Timer failed to deliver message signalled interrupts.
Message
Fields
| Name | Description |
|---|---|
Initialization_status | — |
Status | — |
Event ID 12 — The platform firmware has corrupted memory across the previous system power transition.
Message
Fields
| Name | Description |
|---|---|
Count | — |
FirstPage | — |
LastPage | — |
Event ID 13 — The system watchdog timer was triggered.
Message
Event ID 14 — The watchdog wake timer was triggered.
Message
Event ID 15 — The iommu has detected an error.
Message
Fields
| Name | Description |
|---|---|
SourceId | — |
FaultInformation | — |
FaultReason | — |
ExtendedData | — |
Event ID 16 — IOMMU fault reporting has been initialized.
Message
Example Event
system:
provider: Microsoft-Windows-HAL
guid: 63D1E632-95CC-4443-9312-AF927761D52A
event_source_name: ''
event_id: 16
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:24:57.962026+00:00'
event_record_id: 1635
correlation: {}
execution:
process_id: 4
thread_id: 8
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 17 — The clock interrupt is backed by a platform timer instead of a per-processor source.
Message
Event ID 18 — The performance counter is not readable from user mode.
Message
Event ID 19 — DMA API failure detected.
Message
Fields
| Name | Description |
|---|---|
APIIndex | — |
ErrorCode | — |
FailureInformation1 | — |
FailureInformation2 | — |
Event ID 20 — The hardware real-time clock was not queried because evaluation of the ACPI Time and Alarm Device method failed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 21 — The hardware real-time clock was not set because evaluation of the ACPI Time and Alarm Device method failed.
Message
Fields
| Name | Description |
|---|---|
Status | — |