Microsoft-Windows-Kernel-Dump

12 events across 1 channel

Event ID 1 — AllowCrashDump policy: AllowCrashDump_policy.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpPolicy
Opcode
PolicyOperationFailed

Description

AllowCrashDump policy: AllowCrashDump_policy.

Message #

AllowCrashDump policy: %1.

Fields #

NameDescription
AllowCrashDump_policy AnsiString
OperationType AnsiString
Known values
%%1904
New registry value created
%%1905
Existing registry value modified
%%1906
Registry value deleted
%%14674
Value Added
%%14675
Value Deleted
%%14680
Value Added With Expiration Time
%%14681
Value Deleted With Expiration Time
%%14688
Value Auto Deleted With Expiration Time

Event ID 2 — AllowCrashDump policy value changed (AllowCrashDump = PolicyValue).

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpPolicy
Opcode
PolicyValueChanged

Description

AllowCrashDump policy value changed (AllowCrashDump = PolicyValue). Configure crash dump. NT status: NTStatus.

Message #

AllowCrashDump policy value changed (AllowCrashDump = %1). Configure crash dump. NT status: %2

Fields #

NameDescription
PolicyValue UInt32
NTStatus UInt32

Event ID 3 — CrashDump disabled on boot by policy (AllowCrashDump = PolicyValue).

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpPolicy
Opcode
CrashDumpDisabledOnBoot

Description

CrashDump disabled on boot by policy (AllowCrashDump = PolicyValue).

Message #

CrashDump disabled on boot by policy (AllowCrashDump = %1).

Fields #

NameDescription
PolicyValue UInt32

Event ID 4 — Crash dump disable failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpDisableFailed

Description

Crash dump disable failed. NT status: Crash_dump_disable_failed_NT_status.

Message #

Crash dump disable failed. NT status: %1.

Fields #

NameDescription
Crash_dump_disable_failed_NT_status UInt32Crash dump disable failed. NT status.
NTStatus UInt32

Event ID 5 — Crash dump initialization failed.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Level
Warning
Task
CrashDumpConfig
Opcode
DumpInitializationFailed.

Description

Crash dump initialization failed. NT status: NTStatus.

Message #

Crash dump initialization failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32Crash dump initialization failed. NT status.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-Dump",
    "guid": "17D2A329-4539-5F4D-3435-F510634CE3B9",
    "event_source_name": "",
    "event_id": 5,
    "version": 0,
    "level": 3,
    "task": 2,
    "opcode": 15,
    "keywords": 9223372036854775808,
    "time_created": "2023-10-26T04:16:27.309101+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "Microsoft-Windows-Kernel-Dump/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "NTStatus": 3221225487
  },
  "message": ""
}

References #

Event ID 6 — Crash dump load driver failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpLoadDriverFailed.

Description

Crash dump load driver failed. NT status: Crash_dump_load_driver_failed_NT_status.

Message #

Crash dump load driver failed. NT status: %1.

Fields #

NameDescription
Crash_dump_load_driver_failed_NT_status UInt32Crash dump load driver failed. NT status.
NTStatus UInt32

Event ID 7 — Crash dump dump stack initialization failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpStackInitializationFailed

Description

Crash dump dump stack initialization failed. NT status: NTStatus.

Message #

Crash dump dump stack initialization failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32

Event ID 8 — Crash dump free dump stack failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
FreeDumpStackFailed

Description

Crash dump free dump stack failed. NT status: NTStatus.

Message #

Crash dump free dump stack failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32

Event ID 9 — Crash dump load dump stack failed.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
LoadDumpStackFailed

Description

Crash dump load dump stack failed. NT status: NTStatus.

Message #

Crash dump load dump stack failed. NT status: %1.

Fields #

NameDescription
NTStatus UInt32

Event ID 10 — Crash dump disabled.

#
Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Level
Informational
Task
CrashDumpConfig
Opcode
DumpDisabled

Description

Crash dump disabled.

Message #

Crash dump disabled.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Kernel-Dump",
    "guid": "17D2A329-4539-5F4D-3435-F510634CE3B9",
    "event_source_name": "",
    "event_id": 10,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 20,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-06T06:25:25.603988+00:00",
    "event_record_id": 11,
    "correlation": {},
    "execution": {
      "process_id": 396,
      "thread_id": 408
    },
    "channel": "Microsoft-Windows-Kernel-Dump/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 11 — Crash dump reconfigured.

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
CrashDumpConfig
Opcode
DumpReconfigured

Description

Crash dump reconfigured. NT status: Crash_dump_reconfigured_NT_status.

Message #

Crash dump reconfigured. NT status: %1.

Fields #

NameDescription
Crash_dump_reconfigured_NT_status UInt32Crash dump reconfigured. NT status.
NTStatus UInt32

Event ID 12 — Dump disabled forcefully (ForceDumpDisabled: Dump_disabled_forcefully_ForceDumpDisabled).

Provider
Microsoft-Windows-Kernel-Dump
Channel
Operational
Task
DumpConfig
Opcode
Dumpdisabledforcefully

Description

Dump disabled forcefully (ForceDumpDisabled: Dump_disabled_forcefully_ForceDumpDisabled).

Message #

Dump disabled forcefully (ForceDumpDisabled: %1).

Fields #

NameDescription
Dump_disabled_forcefully_ForceDumpDisabled UInt32Dump disabled forcefully (ForceDumpDisabled.
ForceDumpDisabled UInt32