Microsoft-Windows-Kernel-Dump

12 events across 1 channel

Event ID 1 — AllowCrashDump policy.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

AllowCrashDump policy: %1.

Fields

NameDescription
AllowCrashDump_policy
OperationType

Event ID 2 — AllowCrashDump policy value changed (AllowCrashDump = %1).

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

AllowCrashDump policy value changed (AllowCrashDump = %1). Configure crash dump. NT status: %2

Fields

NameDescription
PolicyValue
NTStatus

Event ID 3 — CrashDump disabled on boot by policy (AllowCrashDump = %1).

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

CrashDump disabled on boot by policy (AllowCrashDump = %1).

Fields

NameDescription
PolicyValue

Event ID 4 — Crash dump disable failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

Crash dump disable failed. NT status: %1.

Fields

NameDescription
Crash_dump_disable_failed_NT_statusCrash dump disable failed. NT status.
NTStatus

Event ID 5 — Crash dump initialization failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Level
3
Samples
1

Message

Crash dump initialization failed. NT status: %1.

Fields

NameDescription
NTStatusCrash dump initialization failed. NT status.

Example Event

system:
  provider: Microsoft-Windows-Kernel-Dump
  guid: 17D2A329-4539-5F4D-3435-F510634CE3B9
  event_source_name: ''
  event_id: 5
  version: 0
  level: 3
  task: 2
  opcode: 15
  keywords: 9223372036854775808
  time_created: '2023-10-26T04:16:27.309101+00:00'
  event_record_id: 1
  correlation: {}
  execution:
    process_id: 4
    thread_id: 8
  channel: Microsoft-Windows-Kernel-Dump/Operational
  computer: WIN-OQ6R0RVA4NF
  security:
    user_id: S-1-5-18
event_data:
  NTStatus: 3221225487
message: ''

References

Event ID 6 — Crash dump load driver failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

Crash dump load driver failed. NT status: %1.

Fields

NameDescription
Crash_dump_load_driver_failed_NT_statusCrash dump load driver failed. NT status.
NTStatus

Event ID 7 — Crash dump dump stack initialization failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

Crash dump dump stack initialization failed. NT status: %1.

Fields

NameDescription
NTStatus

Event ID 8 — Crash dump free dump stack failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

Crash dump free dump stack failed. NT status: %1.

Fields

NameDescription
NTStatus

Event ID 9 — Crash dump load dump stack failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

Crash dump load dump stack failed. NT status: %1.

Fields

NameDescription
NTStatus

Event ID 10 — Crash dump disabled.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Level
4
Samples
1

Message

Crash dump disabled.

Example Event

system:
  provider: Microsoft-Windows-Kernel-Dump
  guid: 17D2A329-4539-5F4D-3435-F510634CE3B9
  event_source_name: ''
  event_id: 10
  version: 0
  level: 4
  task: 2
  opcode: 20
  keywords: 9223372036854775808
  time_created: '2023-11-06T06:25:25.603988+00:00'
  event_record_id: 11
  correlation: {}
  execution:
    process_id: 396
    thread_id: 408
  channel: Microsoft-Windows-Kernel-Dump/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 11 — Crash dump reconfigured.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

Crash dump reconfigured. NT status: %1.

Fields

NameDescription
Crash_dump_reconfigured_NT_statusCrash dump reconfigured. NT status.
NTStatus

Event ID 12 — Dump disabled forcefully (ForceDumpDisabled: %1).

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational

Message

Dump disabled forcefully (ForceDumpDisabled: %1).

Fields

NameDescription
Dump_disabled_forcefully_ForceDumpDisabledDump disabled forcefully (ForceDumpDisabled.
ForceDumpDisabled