Microsoft-Windows-Hyper-V-Hypervisor
118 events across 4 channels
Event ID 1 — Hypervisor successfully started.
Message
Event ID 2 — Hypervisor scheduler type is %1.
Message
Fields
| Name | Description |
|---|---|
SchedulerType | — |
Event ID 3 — Hypervisor Eventlog for global system events could not be created!
Message
Event ID 5 — Hypervisor launch has been disabled through the hypervisorlaunchtype bcdedit setting.
Message
Event ID 10 — Hypervisor Eventlog creation failed!
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 11 — Hypervisor Eventlog deletion failed!
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 12 — Host processor features mask: %1 Host xsave features mask: %2 Host cache line flush size: %3 bytes.
Message
Fields
| Name | Description |
|---|---|
Host_processor_features_mask | — |
Host_xsave_features_mask | — |
Host_cache_line_flush_size | — |
BankCount | — |
ProcessorFeatures | — |
XsaveFeatures | — |
CLFlushSize | — |
Event ID 13 — Hypervisor fails to start ETW tracing session.
Message
Event ID 14 — Hypervisor Eventlog flush failed!
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 20 — Hypervisor launch failed; sleep and hibernate could not be disabled (status %1).
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 26 — Hypervisor launch failed; the hypervisor boot loader's internal logic failed (BalStatus %1, sub-status %2).
Message
Fields
| Name | Description |
|---|---|
BalStatus | — |
Error | — |
Event ID 27 — Hypervisor launch failed; the hypervisor boot loader was unable to allocate sufficient resources to perform the launch.
Message
Event ID 28 — Hypervisor launch failed; the hypervisor boot loader does not support the vendor of at least one of the processors in the system.
Message
Event ID 29 — Hypervisor launch failed; at least one of the processors in the system does not appear to support the features required by the hypervisor.
Message
Fields
| Name | Description |
|---|---|
Leaf | — |
FeaturesRequired | — |
FeaturesPresent | — |
Event ID 31 — Hyper-V launch failed; the system does not appear to have a sufficient level of ACPI support to launch the hypervisor.
Message
Event ID 32 — Hypervisor launch failed; at least one of the processors in the system does not appear to provide a virtualization platform supported by the hyperv...
Message
Event ID 33 — Hyper-V launch failed; the image {ImageName} could not be accessed (status {Status}).
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Status | — |
Event ID 34 — Hyper-V launch failed; the image %1 could not be loaded (status %2).
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Status | — |
Event ID 35 — Hyper-V launch failed; the image {ImageName} could not be read (status {Status}).
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Status | — |
Event ID 36 — Hypervisor launch failed; the image %1 failed code integrity checks, and cannot be used.
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Event ID 37 — Hypervisor launch failed; the image %1 does not contain the image description datastructures, and cannot be used.
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Event ID 38 — Hyper-V launch failed; at least one of the processors in the system was unable to launch the hypervisor (status %1).
Message
Fields
| Name | Description |
|---|---|
BalStatus | — |
Event ID 39 — Hypervisor Load Options - %1.
Message
Fields
| Name | Description |
|---|---|
LoadOptions | — |
Event ID 40 — Hypervisor launch failed; the hypervisor image is revision %1, but the currently installed virtualization software only supports launching revision...
Message
Fields
| Name | Description |
|---|---|
HypervisorVersion | — |
VersionSupported | — |
Event ID 41 — Hypervisor launch failed; Either VMX not present or not enabled in BIOS.
Message
Example Event
system:
provider: Microsoft-Windows-Hyper-V-Hypervisor
guid: 52FC89F8-995E-434C-A91E-199986449890
event_source_name: ''
event_id: 41
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223442405598953472
time_created: '2023-11-06T06:24:56.254005+00:00'
event_record_id: 1627
correlation:
ActivityID: A94F03D9-96B8-C53E-D5D7-00FBA9067B3F
execution:
process_id: 4
thread_id: 8
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 42 — Hypervisor launch failed; Either SVM not present or not enabled in BIOS.
Message
Event ID 43 — Hypervisor launch failed; EL2 not present.
Message
Event ID 44 — Hypervisor launch failed; Either No Execute feature (NX) not present or not enabled in BIOS.
Message
Event ID 46 — Hypervisor launch failed; Processor does not support the minimum features required to run the hypervisor.
Message
Fields
| Name | Description |
|---|---|
MSRIndex | — |
AllowedZeroes | — |
AllowedOnes | — |
Event ID 47 — Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor.
Message
Fields
| Name | Description |
|---|---|
BalStatus | — |
Leaf1Eax | — |
VmCrMsrValue | — |
SvmFeatureEax | — |
HasWorkingSmm | — |
Event ID 48 — Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor.
Message
Fields
| Name | Description |
|---|---|
Leaf | — |
Register | — |
FeaturesNeeded | — |
FeaturesSupported | — |
Event ID 54 — Hypervisor launch failed; Hypervisor image does not match the platform being run on.
Message
Event ID 55 — Hypervisor launch failed; Required firmware table not found.
Message
Event ID 56 — Hypervisor launch failed; Encountered invalid firmware information.
Message
Event ID 59 — Hypervisor launch failed; Second Level Address Translation is required to launch the hypervisor.
Message
Event ID 60 — Hypervisor launch failed; Secure Mode Extensions have been enabled by the BIOS.
Message
Event ID 61 — Hypervisor launch failed; Minimum CPUID leaves required by the hypervisor are not supported on the system.
Message
Event ID 62 — Hypervisor launch failed; The physical address limit supported has been exceeded.
Message
Event ID 63 — Hypervisor launch failed; The hypervisor was unable to initialize successfully (phase %1), and was not started.
Message
Fields
| Name | Description |
|---|---|
Phase | — |
Event ID 64 — Hypervisor launch failed; Too many runtime services memory ranges described by firmware.
Message
Event ID 65 — Hypervisor launch failed; Memory ranges validation failure (BalStatus: %1, BalInternalError: %2, Line: %3, MemoryRangesCount: %4).
Message
Fields
| Name | Description |
|---|---|
BalStatus | — |
BalInternalError | — |
Line | — |
MemoryRangesCount | — |
MemoryRanges | — |
Event ID 80 — Hypervisor launch failed; The operating systems boot loader failed with error %1.
Message
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 81 — Hypervisor launch failed; The operating system boot loader was unable to locate a required resource.
Message
Event ID 82 — Hypervisor launch failed; The operating system boot loader detected a persistent memory failure.
Message
Event ID 83 — Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient memory to complete the operation.
Message
Event ID 84 — Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient resources to complete the operation.
Message
Event ID 85 — Hypervisor launch failed; The operating system boot loader detected a memory map conflict.
Message
Event ID 86 — Hypervisor launch failed; the version of the microcode update dll does not match the current operating system.
Message
Fields
| Name | Description |
|---|---|
ExpectedVersion | — |
ActualVersion | — |
ExpectedFunctionTableSize | — |
ActualFunctionTableSize | — |
UpdateDllName | — |
Event ID 96 — Hypervisor processor startup failed (APIC ID %1, status %2).
Message
Fields
| Name | Description |
|---|---|
CPU | — |
ErrorCode | — |
Event ID 97 — Hypervisor processor startup failed (APIC ID %1) due to CPUID feature validation error.
Message
Fields
| Name | Description |
|---|---|
CPU | — |
LeafNumber | — |
Register | — |
BSPCpuidData | — |
APCpuidData | — |
Event ID 129 — Hypervisor initialized I/O remapping.
Message
Fields
| Name | Description |
|---|---|
Hardware_present | — |
Hardware_enabled | — |
Policy | — |
Enabled_features | — |
Internal_information | — |
Problems | — |
Additional_information | — |
HardwarePresent | — |
HardwareEnabled | — |
EnabledFeatures | — |
InternalInfo | — |
AdditionalInfo | — |
Event ID 130 — Hypervisor I/O remapping is forcibly enabled by policy (the hypervisoriommupolicy BCD option is set to enable).
Message
Event ID 131 — There is an I/O remapping problem with the sytem BIOS.
Message
Fields
| Name | Description |
|---|---|
Problems | — |
Event ID 144 — A device is operating with reduced performance because of a problem with the system BIOS.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
PartitionId | — |
Event ID 145 — A device will not work correctly because of a problem with the system BIOS.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
PartitionId | — |
Event ID 146 — A device will not work correctly because the hypervisor does not have enough resources.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
PartitionId | — |
Event ID 147 — A device will not work correctly because of a problem with the system BIOS.
Message
Fields
| Name | Description |
|---|---|
IoApicId | — |
Event ID 148 — A device could not be used by a child partition because of a limitation of the system hardware and BIOS.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
UnitBaseAddress | — |
PartitionId | — |
Event ID 149 — A device could not be used by a child partition because of a limitation of the system hardware and BIOS.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
PartitionId | — |
Event ID 150 — The image {ImageName} could not be accessed (status {Status}).
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Status | — |
Event ID 151 — The image {ImageName} could not be loaded (status {Status}).
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Status | — |
Event ID 152 — The image %1 could not be read (status %2).
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Status | — |
Event ID 153 — The image %1 failed code integrity checks, and cannot be used.
Message
Fields
| Name | Description |
|---|---|
ImageName | — |
Event ID 154 — Hypervisor failed to properly synchronize TSC across logical processors (Max delta: %1, Min delta: %2).
Message
Fields
| Name | Description |
|---|---|
MaxDelta | — |
MinDelta | — |
Event ID 155 — Host processor features mask: %1 Host xsave features mask: %2 Host cache line flush size: %3 bytes.
Message
Fields
| Name | Description |
|---|---|
Host_processor_features_mask | — |
Host_xsave_features_mask | — |
Host_cache_line_flush_size | — |
BankCount | — |
ProcessorFeatures | — |
XsaveFeatures | — |
CLFlushSize | — |
Event ID 156 — Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.
Message
Fields
| Name | Description |
|---|---|
InitialAllocationNumaPolicy | — |
Event ID 156 — Hypervisor initial page allocation NUMA policy: .
Fields
| Name | Description |
|---|---|
InitialAllocationNumaPolicy | Hypervisor initial page allocation NUMA policy. |
Example Event
system:
provider: Microsoft-Windows-Hyper-V-Hypervisor
guid: 52FC89F8-995E-434C-A91E-199986449890
event_source_name: ''
event_id: 156
version: 1
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:24:56.253950+00:00'
event_record_id: 6
correlation:
ActivityID: A94F03D9-96B8-C53E-D5D7-00FBA9067B3F
execution:
process_id: 4
thread_id: 8
channel: Microsoft-Windows-Hyper-V-Hypervisor-Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
InitialAllocationNumaPolicy: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 157 — The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled and the hyperviso...
Message
Event ID 158 — The queried interface version %1 is not supported (Min : %2, Max : %3).
Message
Fields
| Name | Description |
|---|---|
Max | 1 is not supported (Min. |
CurrentVersion | — |
MinVersion | — |
MaxVersion | — |
Event ID 159 — The queried interface is incomplete.
Message
Event ID 160 — Partition persistence services will be unavailable.
Message
Event ID 161 — The configured Minroot settings are not compatible with the hypervisor core scheduler and have been overriden.
Message
Event ID 162 — Failed to unregister the remote hypercall interface (status %1).
Message
Fields
| Name | Description |
|---|---|
NtStatus | — |
Event ID 163 — The hypervisor encountered an internal error: nested NMI (processor %1).
Message
Fields
| Name | Description |
|---|---|
Processor | — |
Event ID 164 — The hypervisor encountered an internal error: IPI timeout (processor %1).
Message
Fields
| Name | Description |
|---|---|
Processor | — |
Event ID 165 — Hypervisor configured mitigations for CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130 for virtual machines.
Message
Fields
| Name | Description |
|---|---|
NotAffectedMdsNo | — |
NotAffectedAtom | — |
MdClearSupported | — |
BufferFlushNeeded | — |
Event ID 166 — Hypervisor Load Options are conflicting - %1, %2.
Message
Fields
| Name | Description |
|---|---|
LoadOptions | — |
LoadFlags | — |
Event ID 167 — The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled.
Message
Event ID 168 — AMD PSP PCI device discovered.
Message
Fields
| Name | Description |
|---|---|
AMD_PSP_PCI_device_discovered_Segment | AMD PSP PCI device discovered. Segment. |
bus | — |
device | — |
function | — |
Segment | — |
Bus | — |
Device | — |
Function | — |
Event ID 169 — Secure firmware update status.
Message
Fields
| Name | Description |
|---|---|
Secure_firmware_update_status | — |
Status | — |
Event ID 170 — Secure firmware image invalid.
Message
Event ID 171 — Secure firmware version.
Message
Fields
| Name | Description |
|---|---|
Secure_firmware_version | — |
Version | — |
Event ID 172 — Features are enabled that require all processors be started.
Message
Fields
| Name | Description |
|---|---|
RunningProcessors | — |
AvailableProcessors | — |
Event ID 173 — On the prior boot session, the root partition did not respond to the synthetic watchdog in time, triggering a hardware watchdog reboot.
Message
Event ID 8451 — Hyper-V failed creating a new partition (status %1)!
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 12288 —
Fields
| Name | Description |
|---|---|
FailurePhase | — |
NtStatus | — |
Event ID 12289 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12290 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12291 —
Fields
| Name | Description |
|---|---|
PartitionId | — |
NtStatus | — |
AuxiliaryData | — |
Event ID 12292 —
Fields
| Name | Description |
|---|---|
PartitionId | — |
NtStatus | — |
AuxiliaryData | — |
Event ID 12293 —
Fields
| Name | Description |
|---|---|
PartitionId | — |
NtStatus | — |
AuxiliaryData | — |
Event ID 12294 —
Fields
| Name | Description |
|---|---|
PartitionId | — |
NtStatus | — |
AuxiliaryData | — |
Event ID 12295 —
Fields
| Name | Description |
|---|---|
PartitionId | — |
NtStatus | — |
AuxiliaryData | — |
Event ID 12296 —
Fields
| Name | Description |
|---|---|
PartitionId | — |
NtStatus | — |
AuxiliaryData | — |
Event ID 12297 —
Fields
| Name | Description |
|---|---|
TotalSystemPages | — |
TotalPagesRequested | — |
Policy | — |
ProximityDomainCount | — |
AllocationPass | — |
ProximityDomainIndex | — |
ProximityDomainId | — |
TotalDomainPages | — |
PagesRequested | — |
BalStatus | — |
PagesAllocated | — |
Event ID 12298 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12299 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12300 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12301 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12302 —
Fields
| Name | Description |
|---|---|
BalStatus | — |
Event ID 12303 —
Fields
| Name | Description |
|---|---|
HsrInUse | — |
Reason | — |
Event ID 12304 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12305 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12306 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12307 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12308 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12309 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12310 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12311 —
Fields
| Name | Description |
|---|---|
ImageName | — |
Checksum | — |
Timestamp | — |
NtStatus | — |
Event ID 12312 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12313 —
Fields
| Name | Description |
|---|---|
AuxData | — |
NtStatus | — |
Event ID 12314 —
Fields
| Name | Description |
|---|---|
HsrInUse | — |
Reason | — |
Event ID 12315 —
Fields
| Name | Description |
|---|---|
LoadOptions | — |
Event ID 12316 —
Fields
| Name | Description |
|---|---|
LoadOptions | — |
Event ID 12317 —
Fields
| Name | Description |
|---|---|
BaseLocation | — |
Line | — |
BalStatus | — |
AuxData | — |
Event ID 12550 — Hyper-V detected access to a restricted MSR.
Message
Fields
| Name | Description |
|---|---|
Msr | — |
IsWrite | — |
MsrValue | — |
AccessStatus | — |
Pc | — |
ImageBase | — |
ImageChecksum | — |
ImageTimestamp | — |
ImageName | — |
Event ID 16641 — Hyper-V successfully created a new partition (partition %1).
Message
Fields
| Name | Description |
|---|---|
PartitionId | — |
Event ID 16642 — Hyper-V successfully deleted a partition (partition %1).
Message
Fields
| Name | Description |
|---|---|
PartitionId | — |