Microsoft-Windows-Hyper-V-Hypervisor
118 events across 4 channels
Event ID 1 — Hypervisor successfully started.
Description
Hypervisor successfully started.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 1,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223442405598953472,
"time_created": "2026-03-11T06:27:08.616827+00:00",
"event_record_id": 2708,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
Event ID 2 — Hypervisor scheduler type is SchedulerType.
Description
Hypervisor scheduler type is SchedulerType.
Message #
Fields #
| Name | Description |
|---|---|
SchedulerType HexInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 2,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223442405598953472,
"time_created": "2026-03-11T06:27:08.616840+00:00",
"event_record_id": 2709,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"SchedulerType": "0x4"
},
"message": ""
}
Event ID 3 — Hypervisor Eventlog for global system events could not be created!
Description
Hypervisor Eventlog for global system events could not be created!
Message #
Event ID 5 — Hypervisor launch has been disabled through the hypervisorlaunchtype bcdedit setting.
Description
Hypervisor launch has been disabled through the hypervisorlaunchtype bcdedit setting.
Message #
Event ID 10 — Hypervisor Eventlog creation failed!
Event ID 11 — Hypervisor Eventlog deletion failed!
Event ID 12 — Host processor features mask: Host_processor_features_mask.
Event ID 13 — Hypervisor fails to start ETW tracing session.
Description
Hypervisor fails to start ETW tracing session.
Message #
Event ID 14 — Hypervisor Eventlog flush failed!
Event ID 20 — Hypervisor launch failed; sleep and hibernate could not be disabled (status ErrorCode).
Event ID 26 — Hypervisor launch failed; the hypervisor boot loader's internal logic failed (BalStatus BalStatus, sub-status Error).
Event ID 27 — Hypervisor launch failed; the hypervisor boot loader was unable to allocate sufficient resources to perform the launch.
Description
Hypervisor launch failed; the hypervisor boot loader was unable to allocate sufficient resources to perform the launch.
Message #
Event ID 28 — Hypervisor launch failed; the hypervisor boot loader does not support the vendor of at least one of the processors in the system.
Description
Hypervisor launch failed; the hypervisor boot loader does not support the vendor of at least one of the processors in the system.
Message #
Event ID 29 — Hypervisor launch failed; at least one of the processors in the system does not appear to support the features required by the hypervisor.
Event ID 31 — Hyper-V launch failed; the system does not appear to have a sufficient level of ACPI support to launch the hypervisor.
Description
Hyper-V launch failed; the system does not appear to have a sufficient level of ACPI support to launch the hypervisor.
Message #
Event ID 32 — Hypervisor launch failed; at least one of the processors in the system does not appear to provide a virtualization platform supported by the hyperv...
Description
Hypervisor launch failed; at least one of the processors in the system does not appear to provide a virtualization platform supported by the hypervisor.
Message #
Event ID 33 — Hyper-V launch failed; the image {ImageName} could not be accessed (status {Status}).
Description
Hyper-V launch failed; the image {ImageName} could not be accessed (status {Status}).
Message #
Fields #
| Name | Description |
|---|---|
ImageName | — |
Status | — NTSTATUS reference |
Event ID 34 — Hyper-V launch failed; the image ImageName could not be loaded (status Status).
Description
Hyper-V launch failed; the image ImageName could not be loaded (status Status).
Message #
Fields #
| Name | Description |
|---|---|
ImageName UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 35 — Hyper-V launch failed; the image {ImageName} could not be read (status {Status}).
Description
Hyper-V launch failed; the image {ImageName} could not be read (status {Status}).
Message #
Fields #
| Name | Description |
|---|---|
ImageName | — |
Status | — NTSTATUS reference |
Event ID 36 — Hypervisor launch failed; the image ImageName failed code integrity checks, and cannot be used.
Event ID 37 — Hypervisor launch failed; the image ImageName does not contain the image description datastructures, and cannot be used.
Event ID 38 — Hyper-V launch failed; at least one of the processors in the system was unable to launch the hypervisor (status BalStatus).
Event ID 39 — Hypervisor Load Options - LoadOptions.
Description
Hypervisor Load Options - LoadOptions.
Message #
Fields #
| Name | Description |
|---|---|
LoadOptions AnsiString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 39,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-14T01:39:45.534226+00:00",
"event_record_id": 3,
"correlation": {
"ActivityID": "E6C8E93F-24DF-B4AB-98D2-D123EDC8427C"
},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "Microsoft-Windows-Hyper-V-Hypervisor-Admin",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"LoadOptions": " IGNOREMEMPART=1 "
},
"message": ""
}
Event ID 40 — Hypervisor launch failed; the hypervisor image is revision HypervisorVersion, but the currently installed virtualization software only supports launching revision...
Event ID 41 — Hypervisor launch failed; Either VMX not present or not enabled in BIOS.
#Description
Hypervisor launch failed; Either VMX not present or not enabled in BIOS.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 41,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223442405598953472,
"time_created": "2023-11-06T06:24:56.254005+00:00",
"event_record_id": 1627,
"correlation": {
"ActivityID": "A94F03D9-96B8-C53E-D5D7-00FBA9067B3F"
},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 42 — Hypervisor launch failed; Either SVM not present or not enabled in BIOS.
Description
Hypervisor launch failed; Either SVM not present or not enabled in BIOS.
Message #
Event ID 43 — Hypervisor launch failed; EL2 not present.
Description
Hypervisor launch failed; EL2 not present.
Message #
Event ID 44 — Hypervisor launch failed; Either No Execute feature (NX) not present or not enabled in BIOS.
Description
Hypervisor launch failed; Either No Execute feature (NX) not present or not enabled in BIOS.
Message #
Event ID 46 — Hypervisor launch failed; Processor does not support the minimum features required to run the hypervisor.
Event ID 47 — Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor.
Event ID 48 — Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor.
Description
Hypervisor launch failed; Processor does not provide the features necessary to run the hypervisor (leaf Leaf, register Register: features needed FeaturesNeeded, features supported FeaturesSupported).
Message #
Fields #
| Name | Description |
|---|---|
Leaf HexInt32 | — |
Register HexInt32 | — |
FeaturesNeeded HexInt32 | — |
FeaturesSupported HexInt32 | — |
Event ID 54 — Hypervisor launch failed; Hypervisor image does not match the platform being run on.
Description
Hypervisor launch failed; Hypervisor image does not match the platform being run on.
Message #
Event ID 55 — Hypervisor launch failed; Required firmware table not found.
Description
Hypervisor launch failed; Required firmware table not found.
Message #
Event ID 56 — Hypervisor launch failed; Encountered invalid firmware information.
Description
Hypervisor launch failed; Encountered invalid firmware information.
Message #
Event ID 59 — Hypervisor launch failed; Second Level Address Translation is required to launch the hypervisor.
Description
Hypervisor launch failed; Second Level Address Translation is required to launch the hypervisor.
Message #
Event ID 60 — Hypervisor launch failed; Secure Mode Extensions have been enabled by the BIOS.
Description
Hypervisor launch failed; Secure Mode Extensions have been enabled by the BIOS. Please disable Secure Mode Extensions in the BIOS to launch Hyper-V.
Message #
Event ID 61 — Hypervisor launch failed; Minimum CPUID leaves required by the hypervisor are not supported on the system.
Description
Hypervisor launch failed; Minimum CPUID leaves required by the hypervisor are not supported on the system.
Message #
Event ID 62 — Hypervisor launch failed; The physical address limit supported has been exceeded.
Description
Hypervisor launch failed; The physical address limit supported has been exceeded.
Message #
Event ID 63 — Hypervisor launch failed; The hypervisor was unable to initialize successfully (phase Phase), and was not started.
Event ID 64 — Hypervisor launch failed; Too many runtime services memory ranges described by firmware.
Description
Hypervisor launch failed; Too many runtime services memory ranges described by firmware.
Message #
Event ID 65 — Hypervisor launch failed; Memory ranges validation failure (BalStatus: BalStatus, BalInternalError: BalInternalError, Line: Line, MemoryRangesCount: MemoryRangesCount).
Description
Hypervisor launch failed; Memory ranges validation failure (BalStatus: BalStatus, BalInternalError: BalInternalError, Line: Line, MemoryRangesCount: MemoryRangesCount).
Message #
Fields #
| Name | Description |
|---|---|
BalStatus HexInt64 | — |
BalInternalError UInt32 | — |
Line UInt16 | — |
MemoryRangesCount UInt32 | — |
MemoryRanges Int16 | — |
Event ID 80 — Hypervisor launch failed; The operating systems boot loader failed with error NtStatus.
Event ID 81 — Hypervisor launch failed; The operating system boot loader was unable to locate a required resource.
Description
Hypervisor launch failed; The operating system boot loader was unable to locate a required resource.
Message #
Event ID 82 — Hypervisor launch failed; The operating system boot loader detected a persistent memory failure.
Description
Hypervisor launch failed; The operating system boot loader detected a persistent memory failure.
Message #
Event ID 83 — Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient memory to complete the operation.
Description
Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient memory to complete the operation.
Message #
Event ID 84 — Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient resources to complete the operation.
Description
Hypervisor launch failed; The operating system boot loader was unable to allocate sufficient resources to complete the operation.
Message #
Event ID 85 — Hypervisor launch failed; The operating system boot loader detected a memory map conflict.
Description
Hypervisor launch failed; The operating system boot loader detected a memory map conflict.
Message #
Event ID 86 — Hypervisor launch failed; the version of the microcode update dll does not match the current operating system.
Event ID 96 — Hypervisor processor startup failed (APIC ID CPU, status ErrorCode).
Event ID 97 — Hypervisor processor startup failed (APIC ID CPU) due to CPUID feature validation error.
Event ID 129 — Hypervisor initialized I/O remapping.
Description
Hypervisor initialized I/O remapping.
Message #
Fields #
| Name | Description |
|---|---|
HardwarePresent Boolean | — |
HardwareEnabled Boolean | — |
Policy HexInt64 | — |
EnabledFeatures HexInt64 | — |
InternalInfo HexInt64 | — |
Problems HexInt64 | — |
AdditionalInfo HexInt64 | — |
Hardware_present Boolean | — |
Hardware_enabled Boolean | — |
Enabled_features HexInt64 | — |
Internal_information HexInt64 | — |
Additional_information HexInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 129,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223442405598953472,
"time_created": "2026-03-11T06:27:08.616876+00:00",
"event_record_id": 2710,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"HardwarePresent": false,
"HardwareEnabled": false,
"Policy": "0x0",
"EnabledFeatures": "0x0",
"InternalInfo": "0x0",
"Problems": "0x0",
"AdditionalInfo": "0x0"
},
"message": ""
}
Event ID 130 — Hypervisor I/O remapping is forcibly enabled by policy (the hypervisoriommupolicy BCD option is set to enable).
Message #
Event ID 131 — There is an I/O remapping problem with the sytem BIOS.
Event ID 144 — A device is operating with reduced performance because of a problem with the system BIOS.
Event ID 145 — A device will not work correctly because of a problem with the system BIOS.
Event ID 146 — A device will not work correctly because the hypervisor does not have enough resources.
Event ID 147 — A device will not work correctly because of a problem with the system BIOS.
Event ID 148 — A device could not be used by a child partition because of a limitation of the system hardware and BIOS.
Event ID 149 — A device could not be used by a child partition because of a limitation of the system hardware and BIOS.
Event ID 150 — The image {ImageName} could not be accessed (status {Status}).
Description
The image {ImageName} could not be accessed (status {Status}).
Message #
Fields #
| Name | Description |
|---|---|
ImageName | — |
Status | — NTSTATUS reference |
Event ID 151 — The image {ImageName} could not be loaded (status {Status}).
Description
The image {ImageName} could not be loaded (status {Status}).
Message #
Fields #
| Name | Description |
|---|---|
ImageName | — |
Status | — NTSTATUS reference |
Event ID 152 — The image ImageName could not be read (status Status).
Description
The image ImageName could not be read (status Status).
Message #
Fields #
| Name | Description |
|---|---|
ImageName UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 153 — The image ImageName failed code integrity checks, and cannot be used.
Event ID 154 — Hypervisor failed to properly synchronize TSC across logical processors (Max delta: MaxDelta, Min delta: MinDelta).
Event ID 155 — Host processor features mask: BankCount.
Description
Host processor features mask: BankCount.
Message #
Fields #
| Name | Description |
|---|---|
BankCount UInt8 | — |
ProcessorFeatures HexInt64 | — |
XsaveFeatures HexInt64 | — |
CLFlushSize UInt32 | — |
Host_processor_features_mask | — |
Host_xsave_features_mask | — |
Host_cache_line_flush_size | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 155,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:24.431418+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 364
},
"channel": "Microsoft-Windows-Hyper-V-Hypervisor-Admin",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"BankCount": 2,
"ProcessorFeatures": "0x800040",
"XsaveFeatures": "0x1f",
"CLFlushSize": 64
},
"message": ""
}
Event ID 156 — Hypervisor initial page allocation NUMA policy: .
#Description
Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.
Fields #
| Name | Description |
|---|---|
InitialAllocationNumaPolicy UInt32 | Hypervisor initial page allocation NUMA policy. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 156,
"version": 1,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:24:56.253950+00:00",
"event_record_id": 6,
"correlation": {
"ActivityID": "A94F03D9-96B8-C53E-D5D7-00FBA9067B3F"
},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "Microsoft-Windows-Hyper-V-Hypervisor-Admin",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"InitialAllocationNumaPolicy": 0
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 156 — Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.
Description
Hypervisor configured mitigations for CVE-2018-3646 for virtual machines.
Message #
Fields #
| Name | Description |
|---|---|
NotAffectedRdclNo | — |
NotAffectedAtom | — |
CacheFlushSupported | — |
SmtEnabled | — |
ParentHypervisorFlushes | — |
DisabledLoadOption | — |
Enabled | — |
CacheFlushNeeded | — |
InitialAllocationNumaPolicy UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 156,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223442405598953472,
"time_created": "2026-03-11T06:27:08.616901+00:00",
"event_record_id": 2711,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NotAffectedRdclNo": false,
"NotAffectedAtom": false,
"CacheFlushSupported": true,
"SmtEnabled": false,
"ParentHypervisorFlushes": false,
"DisabledLoadOption": false,
"Enabled": true,
"CacheFlushNeeded": true
},
"message": ""
}
Event ID 157 — The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled and the hyperviso...
Message #
Event ID 158 — The queried interface version Max is not supported (Min : CurrentVersion, Max : MinVersion).
Event ID 159 — The queried interface is incomplete.
Description
The queried interface is incomplete.
Message #
Event ID 160 — Partition persistence services will be unavailable.
Description
Partition persistence services will be unavailable.
Message #
Event ID 161 — The configured Minroot settings are not compatible with the hypervisor core scheduler and have been overriden.
Description
The configured Minroot settings are not compatible with the hypervisor core scheduler and have been overriden. This may expose a different number of logical processors to the root partition.
Message #
Event ID 162 — Failed to unregister the remote hypercall interface (status NtStatus).
Event ID 163 — The hypervisor encountered an internal error: nested NMI (processor Processor).
Event ID 164 — The hypervisor encountered an internal error: IPI timeout (processor Processor).
Event ID 165 — Hypervisor configured mitigations for CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130 for virtual machines.
Description
Hypervisor configured mitigations for CVE-2019-11091, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130 for virtual machines.
Message #
Fields #
| Name | Description |
|---|---|
NotAffectedMdsNo Boolean | — |
NotAffectedAtom Boolean | — |
MdClearSupported Boolean | — |
BufferFlushNeeded Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 165,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223442405598953472,
"time_created": "2026-03-11T06:27:08.616931+00:00",
"event_record_id": 2712,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NotAffectedMdsNo": false,
"NotAffectedAtom": false,
"MdClearSupported": true,
"BufferFlushNeeded": true
},
"message": ""
}
Event ID 166 — Hypervisor Load Options are conflicting - LoadOptions, LoadFlags.
Event ID 167 — The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled.
Description
The hypervisor did not enable mitigations for side channel vulnerabilities for virtual machines because HyperThreading is enabled. To enable mitigations for virtual machines, disable HyperThreading.
Message #
Event ID 168 — AMD PSP PCI device discovered.
Description
AMD PSP PCI device discovered. Segment: AMD_PSP_PCI_device_discovered_Segment, bus: bus, device: device, function: function.
Message #
Fields #
| Name | Description |
|---|---|
AMD_PSP_PCI_device_discovered_Segment UInt16 | AMD PSP PCI device discovered. Segment. |
bus UInt8 | — |
device UInt8 | — |
function UInt8 | — |
Segment UInt16 | — |
Bus UInt8 | — |
Device UInt8 | — |
Function UInt8 | — |
Event ID 169 — Secure firmware update status: Secure_firmware_update_status.
Description
Secure firmware update status: Secure_firmware_update_status.
Message #
Fields #
| Name | Description |
|---|---|
Secure_firmware_update_status UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 170 — Secure firmware image invalid.
Description
Secure firmware image invalid.
Message #
Event ID 171 — Secure firmware version: Secure_firmware_version.
Event ID 172 — Features are enabled that require all processors be started.
Event ID 173 — On the prior boot session, the root partition did not respond to the synthetic watchdog in time, triggering a hardware watchdog reboot.
Description
On the prior boot session, the root partition did not respond to the synthetic watchdog in time, triggering a hardware watchdog reboot.
Message #
Event ID 8451 — Hyper-V failed creating a new partition (status Error)!
Event ID 12288 —
Fields #
| Name | Description |
|---|---|
FailurePhase UInt32 | — |
NtStatus UInt32 | — |
Event ID 12289 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12290 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12291 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
NtStatus UInt32 | — |
AuxiliaryData UInt64 | — |
Event ID 12292 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
NtStatus UInt32 | — |
AuxiliaryData UInt64 | — |
Event ID 12293 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
NtStatus UInt32 | — |
AuxiliaryData UInt64 | — |
Event ID 12294 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
NtStatus UInt32 | — |
AuxiliaryData UInt64 | — |
Event ID 12295 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
NtStatus UInt32 | — |
AuxiliaryData UInt64 | — |
Event ID 12296 —
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
NtStatus UInt32 | — |
AuxiliaryData UInt64 | — |
Event ID 12297 —
Fields #
| Name | Description |
|---|---|
TotalSystemPages HexInt64 | — |
TotalPagesRequested HexInt32 | — |
Policy UInt32 | — |
ProximityDomainCount UInt32 | — |
AllocationPass UInt32 | — |
ProximityDomainIndex UInt32 | — |
ProximityDomainId HexInt32 | — |
TotalDomainPages HexInt64 | — |
PagesRequested HexInt32 | — |
BalStatus HexInt64 | — |
PagesAllocated HexInt32 | — |
Event ID 12298 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12299 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12300 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12301 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12302 —
Fields #
| Name | Description |
|---|---|
BalStatus HexInt64 | — |
Event ID 12303 —
Fields #
| Name | Description |
|---|---|
HsrInUse Boolean | — |
Reason UInt32 | — |
Event ID 12304 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12305 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12306 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12307 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12308 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12309 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12310 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12311 —
Fields #
| Name | Description |
|---|---|
ImageName UnicodeString | — |
Checksum UInt32 | — |
Timestamp UInt32 | — |
NtStatus UInt32 | — |
Event ID 12312 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12313 —
Fields #
| Name | Description |
|---|---|
AuxData UInt64 | — |
NtStatus UInt32 | — |
Event ID 12314 —
Fields #
| Name | Description |
|---|---|
HsrInUse Boolean | — |
Reason UInt32 | — |
Event ID 12315 —
Fields #
| Name | Description |
|---|---|
LoadOptions AnsiString | — |
Event ID 12316 —
Fields #
| Name | Description |
|---|---|
LoadOptions AnsiString | — |
Event ID 12317 —
Fields #
| Name | Description |
|---|---|
BaseLocation AnsiString | — |
Line UInt32 | — |
BalStatus HexInt64 | — |
AuxData UInt64 | — |
Event ID 12550 — Hyper-V detected access to a restricted MSR.
Description
Hyper-V detected access to a restricted MSR (Msr: Msr, IsWrite: IsWrite, MsrValue: MsrValue, AccessStatus: AccessStatus, Pc: Pc, ImageBase: ImageBase, ImageChecksum: ImageChecksum, ImageTimestamp: ImageTimestamp, ImageName: ImageName).
Message #
Fields #
| Name | Description |
|---|---|
Msr HexInt32 | — |
IsWrite UInt8 | — |
MsrValue HexInt64 | — |
AccessStatus UInt16 | — |
Pc HexInt64 | — |
ImageBase HexInt64 | — |
ImageChecksum HexInt32 | — |
ImageTimestamp HexInt32 | — |
ImageName AnsiString | — |
Event ID 16641 — Hyper-V successfully created a new partition (partition PartitionId).
Description
Hyper-V successfully created a new partition (partition PartitionId).
Message #
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 16641,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 2305843009213693952,
"time_created": "2026-03-11T06:32:05.545260+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 2472
},
"channel": "Microsoft-Windows-Hyper-V-Hypervisor-Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PartitionId": 2
},
"message": ""
}
Event ID 16642 — Hyper-V successfully deleted a partition (partition PartitionId).
Description
Hyper-V successfully deleted a partition (partition PartitionId).
Message #
Fields #
| Name | Description |
|---|---|
PartitionId UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Hypervisor",
"guid": "52FC89F8-995E-434C-A91E-199986449890",
"event_source_name": "",
"event_id": 16642,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 2305843009213693952,
"time_created": "2026-03-13T20:09:16.550106+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 424
},
"channel": "Microsoft-Windows-Hyper-V-Hypervisor-Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PartitionId": 2
},
"message": ""
}