Microsoft-Windows-Kernel-LiveDump
60 events across 2 channels
Event ID 1 — Live Dump Capture Dump Data API started.
Message
Fields
| Name | Description |
|---|---|
ControlFlags | — |
AddPagesControl | — |
Event ID 2 — Live Dump Capture Dump Data API ended.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
BugcheckCode | — |
BugCheckParameter1 | — |
BugCheckParameter2 | — |
BugCheckParameter3 | — |
BugCheckParameter4 | — |
AbortIfMemoryPressure | — |
DumpCaptureDuration_ms | — |
SelectiveDump | — |
DynamicLowMemoryThresholdBytes | — |
AvailablePhysicalMemoryInBytes | — |
TotalPhysicalMemoryInBytes | — |
IOSpaceEnabled | — |
Event ID 3 — Writing dump file started.
Message
Event ID 4 — Writing dump file ended.
Message
Fields
| Name | Description |
|---|---|
Writing_dump_file_ended_NT_Status | Writing dump file ended. NT Status. |
NTStatus | — |
TotalBytes | — |
HeaderBytes | — |
PrimaryDataBytes | — |
SecondaryDataBytes | — |
DumpWriteDuration_ms | — |
Event ID 5 — Live Dump request aborted due to memory pressure on system
Message
Event ID 6 — LiveDump Event Generic
Message
Fields
| Name | Description |
|---|---|
LiveDumpEventDescription | — |
Parameter1Name | — |
Parameter1Value | — |
Parameter2Name | — |
Parameter2Value | — |
Parameter3Name | — |
Parameter3Value | — |
Parameter4Name | — |
Parameter4Value | — |
Parameter5Name | — |
Parameter5Value | — |
Parameter6Name | — |
Parameter6Value | — |
Parameter7Name | — |
Parameter7Value | — |
Parameter8Name | — |
Parameter8Value | — |
Event ID 101 — Sizing Workflow: Mirroring started.
Message
Event ID 102 — Sizing Workflow: Mirroring Phase 0 ended.
Message
Event ID 103 — Sizing Workflow: Mirroring Phase 1 ended.
Message
Event ID 104 — Sizing Workflow: System Quiesce started.
Message
Event ID 105 — Sizing Workflow: System Quiesce ended.
Message
Event ID 106 — Sizing Workflow: Estimation.
Message
Fields
| Name | Description |
|---|---|
Sizing_Workflow_Estimation_NT | — |
NtEstimatedRequiredPrimaryDataBytes | — |
NtEstimatedPrimaryDataBytes | — |
HvEstimatedPrimaryDataBytes | — |
HvEstimatedSecondaryDataBytes | — |
SkEstimatedPrimaryDataBytes | — |
MemoryEstimationDuration_ms | — |
SystemQuiescedDuration_ms | — |
EndMirroringPhasesDuration_ms | — |
MirrorPhysicalMemoryDuration_ms | — |
MirrorPhysicalMemorySizeInBytes | — |
HvlCalculateLiveDumpSizeDuration_ms | — |
Event ID 107 — Sizing Workflow: Allocation.
Message
Fields
| Name | Description |
|---|---|
Sizing_Workflow_Allocation_NT | Sizing Workflow: Allocation. NT. |
NtPrimaryDataBytes | — |
HvPrimaryDataBytes | — |
HvSecondaryDataBytes | — |
SkPrimaryDataBytes | — |
AllocateDumpBuffersDuration_ms | — |
AllocateExtraBuffersDuration_ms | — |
HvlPrepareLivedumpDescriptorDuration_ms | — |
Event ID 108 — Sizing Workflow: RemovePages Callbacks started.
Message
Event ID 109 — Sizing Workflow: RemovePages Callbacks ended.
Message
Event ID 110 — Sizing Workflow: RemovePages Callback %1 started.
Message
Fields
| Name | Description |
|---|---|
CallbackIdentifier | — |
Event ID 111 — Sizing Workflow: RemovePages Callback %1 ended.
Message
Fields
| Name | Description |
|---|---|
CallbackIdentifier | — |
Event ID 112 — Sizing Workflow: RemovePages Callback %1 failed.
Message
Fields
| Name | Description |
|---|---|
CallbackIdentifier | — |
NTStatus | — |
Event ID 113 — Sizing workflow: %1 pages estimated to be allocated and %2 pages allocated.
Message
Fields
| Name | Description |
|---|---|
Sizing_workflow | — |
Dump_file_size_limit | — |
bytes_Dump_file_size_limit_reached | — |
Aborted_while_buffer_allocation | — |
EstimatedPageCount | — |
AllocatedPageCount | — |
VMMemoryPartitionIOSpaceAllocatedPages | — |
VMMemoryPartitionAllocatedPages | — |
SystemPartitionIOSpaceAllocatedPages | — |
SystemPartitionAllocatedPages | — |
LimitDumpFileSize | — |
DumpFileSizeLimitInBytes | — |
DumpFileSizeLimitReached | — |
AbortWhileBufferAllocation | — |
Event ID 114 — Sizing Workflow: Query Hvl for dump size failed.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
Event ID 115 — Sizing Workflow: Open VM memory partition failed.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
Event ID 116 — Sizing Workflow: Buffer allocation from the VM memory partition failed.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
Event ID 117 — Sizing Workflow: Capture processor context when the system is quiesced.
Message
Fields
| Name | Description |
|---|---|
Duration_ms | — |
Event ID 118 — Sizing Workflow: Mark required dump data when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
MarkRequiredDumpDataDuration_ms | — |
Event ID 119 — Sizing Workflow: Mark important dump data when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
MarkImportantDumpDataDuration_ms | — |
Event ID 120 — Sizing Workflow: Populate bitmap for dump when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
PopulateBitmapForDumpDuration_ms | — |
RemoveSystemCacheFromDumpDuration_ms | — |
Event ID 121 — Sizing Workflow: Corral processors to quiesce the system.
Message
Fields
| Name | Description |
|---|---|
CorralDuration_ms | — |
DisableInterruptsDuration_ms | — |
SaveSupervisorStateDuration_ms | — |
SuspendClockTimerDuration_ms | — |
Event ID 122 — Sizing Workflow: Uncorral processors to quiesce the system.
Message
Fields
| Name | Description |
|---|---|
UncorralDuration_ms | — |
EnableInterruptsDuration_ms | — |
RestoreSupervisorStateDuration_ms | — |
ResumeClockTimerDuration_ms | — |
Event ID 123 — Sizing Workflow: MmDuplicateMemory failed.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
MirrorInProgress | — |
Event ID 124 — IO space utilization disabled when HV/SK pages requested, NoSecrets mode disabled, and SK running.
Message
Event ID 125 — Callout for %1 (included %2).
Message
Fields
| Name | Description |
|---|---|
Callout | — |
Included | — |
Event ID 126 — Sizing Workflow: Call to Hvl for preparing livedump descriptor failed.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
Event ID 151 — Capture Pages Workflow: Mirroring started.
Message
Event ID 152 — Capture Pages Workflow: Mirroring Phase 0 ended.
Message
Event ID 153 — Capture Pages Workflow: Mirroring Phase 1 ended.
Message
Event ID 154 — Capture Pages Workflow: System Quiesce started.
Message
Event ID 155 — Capture Pages Workflow: System Quiesce ended.
Message
Event ID 156 — Capture Pages Workflow: Copy memory pages started.
Message
Event ID 157 — Capture Pages Workflow: Copy memory pages ended.
Message
Event ID 158 — Capture Pages Workflow: Capture processor context when the system is quiesced.
Message
Fields
| Name | Description |
|---|---|
Duration_ms | — |
Event ID 159 — Capture Pages Workflow: Mark required dump data when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
MarkRequiredDumpDataDuration_ms | — |
Event ID 160 — Capture Pages Workflow: Mark important dump data when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
MarkImportantDumpDataDuration_ms | — |
Event ID 161 — Capture Pages Workflow: Populate bitmap for dump when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
PopulateBitmapForDumpDuration_ms | — |
RemoveSystemCacheFromDumpDuration_ms | — |
Event ID 162 — Capture Pages Workflow: Collect Hvl dump when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
Duration_ms | — |
Event ID 163 — Capture Pages Workflow: Generate Ipt secondary data when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
Duration_ms | — |
Event ID 164 — Capture Pages Workflow: Initiate state change to copy contents of marked pages when system is quiesced.
Message
Fields
| Name | Description |
|---|---|
Duration_ms | — |
Event ID 165 — Capture Pages Workflow: Corral processors to quiesce the system.
Message
Fields
| Name | Description |
|---|---|
CorralDuration_ms | — |
DisableInterruptsDuration_ms | — |
SaveSupervisorStateDuration_ms | — |
SuspendClockTimerDuration_ms | — |
Event ID 166 — Capture Pages Workflow: Uncorral processors to quiesce the system.
Message
Fields
| Name | Description |
|---|---|
UncorralDuration_ms | — |
EnableInterruptsDuration_ms | — |
RestoreSupervisorStateDuration_ms | — |
ResumeClockTimerDuration_ms | — |
Event ID 167 — Capture Pages Workflow: Capture memory pages.
Message
Fields
| Name | Description |
|---|---|
MemoryCaptureDuration_ms | — |
SystemQuiescedDuration_ms | — |
EndMirroringPhasesDuration_ms | — |
MirrorPhysicalMemoryDuration_ms | — |
MirrorPhysicalMemorySizeInBytes | — |
HvlCollectLivedumpDuration_ms | — |
DumpDataBufferingDuration_ms | — |
Event ID 168 — Capture Pages Workflow: MmDuplicateMemory failed.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
MirrorInProgress | — |
Event ID 169 — Callout for %1 (included %2).
Message
Fields
| Name | Description |
|---|---|
Callout | — |
Included | — |
Event ID 201 — Live Dump Write Deferred Dump Data API started.
Message
Event ID 202 — Live Dump Write Deferred Dump Data API ended.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
BugcheckCode | — |
BugCheckParameter1 | — |
BugCheckParameter2 | — |
BugCheckParameter3 | — |
BugCheckParameter4 | — |
AbortIfMemoryPressure | — |
DumpCaptureDuration_ms | — |
SelectiveDump | — |
DynamicLowMemoryThresholdBytes | — |
AvailablePhysicalMemoryInBytes | — |
TotalPhysicalMemoryInBytes | — |
IOSpaceEnabled | — |
Event ID 203 — Write deferred dump data to file started.
Message
Event ID 204 — Write deferred dump data to file ended.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
TotalBytes | — |
HeaderBytes | — |
PrimaryDataBytes | — |
SecondaryDataBytes | — |
DumpWriteDuration_ms | — |
Event ID 251 — Live Dump Discard Deferred Dump Data API started.
Message
Event ID 252 — Live Dump Discard Deferred Dump Data API ended.
Message
Fields
| Name | Description |
|---|---|
NTStatus | — |
BugcheckCode | — |
BugCheckParameter1 | — |
BugCheckParameter2 | — |
BugCheckParameter3 | — |
BugCheckParameter4 | — |
AbortIfMemoryPressure | — |
DumpCaptureDuration_ms | — |
SelectiveDump | — |
DynamicLowMemoryThresholdBytes | — |
AvailablePhysicalMemoryInBytes | — |
TotalPhysicalMemoryInBytes | — |
IOSpaceEnabled | — |
Event ID 271 — AllowLiveDump policy.
Message
Fields
| Name | Description |
|---|---|
AllowLiveDump_policy | — |
OperationType | — |
Event ID 272 — AllowLiveDump policy value changed (AllowLiveDump = %1).
Message
Fields
| Name | Description |
|---|---|
PolicyValue | — |
NTStatus | — |
Event ID 273 — LiveDump disabled on boot by policy (AllowLiveDump = %1).
Message
Fields
| Name | Description |
|---|---|
PolicyValue | — |