Microsoft-Windows-Kernel-LiveDump
60 events across 2 channels
Event ID 1 — Live Dump Capture Dump Data API started.
Event ID 2 — Live Dump Capture Dump Data API ended.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | — |
BugcheckCode UInt32 | — |
BugCheckParameter1 Pointer | — |
BugCheckParameter2 Pointer | — |
BugCheckParameter3 Pointer | — |
BugCheckParameter4 Pointer | — |
AbortIfMemoryPressure UInt32 | — |
DumpCaptureDuration_ms UInt64 | — |
SelectiveDump UInt32 | — |
DynamicLowMemoryThresholdBytes UInt64 | — |
AvailablePhysicalMemoryInBytes UInt64 | — |
TotalPhysicalMemoryInBytes UInt64 | — |
IOSpaceEnabled Boolean | — |
Event ID 3 — Writing dump file started.
Description
Writing dump file started.
Message #
Event ID 4 — Writing dump file ended.
Description
Writing dump file ended. NT Status: Writing_dump_file_ended_NT_Status. Total NTStatus bytes (Header|Primary|Secondary: TotalBytes|HeaderBytes|PrimaryDataBytes bytes). DumpWriteDuration: SecondaryDataBytesms.
Message #
Fields #
| Name | Description |
|---|---|
Writing_dump_file_ended_NT_Status | Writing dump file ended. NT Status. |
NTStatus UInt32 | — |
TotalBytes UInt64 | — |
HeaderBytes UInt64 | — |
PrimaryDataBytes UInt64 | — |
SecondaryDataBytes UInt64 | — |
DumpWriteDuration_ms UInt64 | — |
Event ID 5 — Live Dump request aborted due to memory pressure on system
Description
Live Dump request aborted due to memory pressure on system.
Message #
Event ID 6 — LiveDump Event Generic
Description
LiveDump Event Generic.
Message #
Fields #
| Name | Description |
|---|---|
LiveDumpEventDescription UnicodeString | — |
Parameter1Name UnicodeString | — |
Parameter1Value UInt64 | — |
Parameter2Name UnicodeString | — |
Parameter2Value UInt64 | — |
Parameter3Name UnicodeString | — |
Parameter3Value UInt64 | — |
Parameter4Name UnicodeString | — |
Parameter4Value UInt64 | — |
Parameter5Name UnicodeString | — |
Parameter5Value UInt64 | — |
Parameter6Name UnicodeString | — |
Parameter6Value UInt64 | — |
Parameter7Name UnicodeString | — |
Parameter7Value UInt64 | — |
Parameter8Name UnicodeString | — |
Parameter8Value UInt64 | — |
Event ID 101 — Sizing Workflow: Mirroring started.
Description
Sizing Workflow: Mirroring started.
Message #
Event ID 102 — Sizing Workflow: Mirroring Phase 0 ended.
Description
Sizing Workflow: Mirroring Phase 0 ended.
Message #
Event ID 103 — Sizing Workflow: Mirroring Phase 1 ended.
Description
Sizing Workflow: Mirroring Phase 1 ended.
Message #
Event ID 104 — Sizing Workflow: System Quiesce started.
Description
Sizing Workflow: System Quiesce started.
Message #
Event ID 105 — Sizing Workflow: System Quiesce ended.
Description
Sizing Workflow: System Quiesce ended.
Message #
Event ID 106 — Sizing Workflow: Estimation.
Description
Sizing Workflow: Estimation. NT: NtEstimatedRequiredPrimaryDataBytes bytes (Minimum Sizing_Workflow_Estimation_NT bytes). Hypervisor: Primary NtEstimatedPrimaryDataBytes bytes. Secondary HvEstimatedPrimaryDataBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
Sizing_Workflow_Estimation_NT | — |
NtEstimatedRequiredPrimaryDataBytes UInt64 | — |
NtEstimatedPrimaryDataBytes UInt64 | — |
HvEstimatedPrimaryDataBytes UInt64 | — |
HvEstimatedSecondaryDataBytes UInt64 | — |
SkEstimatedPrimaryDataBytes UInt64 | — |
MemoryEstimationDuration_ms UInt64 | — |
SystemQuiescedDuration_ms UInt64 | — |
EndMirroringPhasesDuration_ms UInt64 | — |
MirrorPhysicalMemoryDuration_ms UInt64 | — |
MirrorPhysicalMemorySizeInBytes UInt64 | — |
HvlCalculateLiveDumpSizeDuration_ms UInt64 | — |
Event ID 107 — Sizing Workflow: Allocation.
Description
Sizing Workflow: Allocation. NT: Sizing_Workflow_Allocation_NT bytes. Hypervisor: Primary NtPrimaryDataBytes bytes. Secondary HvPrimaryDataBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
Sizing_Workflow_Allocation_NT | Sizing Workflow: Allocation. NT. |
NtPrimaryDataBytes UInt64 | — |
HvPrimaryDataBytes UInt64 | — |
HvSecondaryDataBytes UInt64 | — |
SkPrimaryDataBytes UInt64 | — |
AllocateDumpBuffersDuration_ms UInt64 | — |
AllocateExtraBuffersDuration_ms UInt64 | — |
HvlPrepareLivedumpDescriptorDuration_ms UInt64 | — |
Event ID 108 — Sizing Workflow: RemovePages Callbacks started.
Description
Sizing Workflow: RemovePages Callbacks started.
Message #
Event ID 109 — Sizing Workflow: RemovePages Callbacks ended.
Description
Sizing Workflow: RemovePages Callbacks ended.
Message #
Event ID 110 — Sizing Workflow: RemovePages Callback CallbackIdentifier started.
Event ID 111 — Sizing Workflow: RemovePages Callback CallbackIdentifier ended.
Event ID 112 — Sizing Workflow: RemovePages Callback CallbackIdentifier failed.
Event ID 113 — Sizing workflow: Sizing_workflow pages estimated to be allocated and Dump_file_size_limit pages allocated.
Message #
Fields #
| Name | Description |
|---|---|
Sizing_workflow | — |
Dump_file_size_limit | — |
bytes_Dump_file_size_limit_reached | — |
Aborted_while_buffer_allocation | — |
EstimatedPageCount UInt64 | — |
AllocatedPageCount UInt64 | — |
VMMemoryPartitionIOSpaceAllocatedPages UInt64 | — |
VMMemoryPartitionAllocatedPages UInt64 | — |
SystemPartitionIOSpaceAllocatedPages UInt64 | — |
SystemPartitionAllocatedPages UInt64 | — |
LimitDumpFileSize UInt32 | — |
DumpFileSizeLimitInBytes UInt64 | — |
DumpFileSizeLimitReached UInt32 | — |
AbortWhileBufferAllocation UInt32 | — |
Event ID 114 — Sizing Workflow: Query Hvl for dump size failed.
Event ID 115 — Sizing Workflow: Open VM memory partition failed.
Event ID 116 — Sizing Workflow: Buffer allocation from the VM memory partition failed.
Event ID 117 — Sizing Workflow: Capture processor context when the system is quiesced.
Event ID 118 — Sizing Workflow: Mark required dump data when system is quiesced.
Event ID 119 — Sizing Workflow: Mark important dump data when system is quiesced.
Event ID 120 — Sizing Workflow: Populate bitmap for dump when system is quiesced.
Description
Sizing Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: PopulateBitmapForDumpDuration_msms. RemoveSystemCacheFromDumpDuration RemoveSystemCacheFromDumpDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
PopulateBitmapForDumpDuration_ms UInt64 | — |
RemoveSystemCacheFromDumpDuration_ms UInt64 | — |
Event ID 121 — Sizing Workflow: Corral processors to quiesce the system.
Description
Sizing Workflow: Corral processors to quiesce the system. CorralDuration: CorralDuration_msms. DisableInterruptsDuration: DisableInterruptsDuration_msms. SaveSupervisorStateDuration: SaveSupervisorStateDuration_msms. SuspendClockTimerDuration: SuspendClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
CorralDuration_ms UInt64 | — |
DisableInterruptsDuration_ms UInt64 | — |
SaveSupervisorStateDuration_ms UInt64 | — |
SuspendClockTimerDuration_ms UInt64 | — |
Event ID 122 — Sizing Workflow: Uncorral processors to quiesce the system.
Description
Sizing Workflow: Uncorral processors to quiesce the system. UncorralDuration: UncorralDuration_msms. EnableInterruptsDuration: EnableInterruptsDuration_msms. RestoreSupervisorStateDuration: RestoreSupervisorStateDuration_msms. ResumeClockTimerDuration: ResumeClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
UncorralDuration_ms UInt64 | — |
EnableInterruptsDuration_ms UInt64 | — |
RestoreSupervisorStateDuration_ms UInt64 | — |
ResumeClockTimerDuration_ms UInt64 | — |
Event ID 123 — Sizing Workflow: MmDuplicateMemory failed.
Event ID 124 — IO space utilization disabled when HV/SK pages requested, NoSecrets mode disabled, and SK running.
Description
IO space utilization disabled when HV/SK pages requested, NoSecrets mode disabled, and SK running.
Message #
Event ID 125 — Callout for Callout (included Included).
Event ID 126 — Sizing Workflow: Call to Hvl for preparing livedump descriptor failed.
Event ID 151 — Capture Pages Workflow: Mirroring started.
Description
Capture Pages Workflow: Mirroring started.
Message #
Event ID 152 — Capture Pages Workflow: Mirroring Phase 0 ended.
Description
Capture Pages Workflow: Mirroring Phase 0 ended.
Message #
Event ID 153 — Capture Pages Workflow: Mirroring Phase 1 ended.
Description
Capture Pages Workflow: Mirroring Phase 1 ended.
Message #
Event ID 154 — Capture Pages Workflow: System Quiesce started.
Description
Capture Pages Workflow: System Quiesce started.
Message #
Event ID 155 — Capture Pages Workflow: System Quiesce ended.
Description
Capture Pages Workflow: System Quiesce ended.
Message #
Event ID 156 — Capture Pages Workflow: Copy memory pages started.
Description
Capture Pages Workflow: Copy memory pages started.
Message #
Event ID 157 — Capture Pages Workflow: Copy memory pages ended.
Description
Capture Pages Workflow: Copy memory pages ended.
Message #
Event ID 158 — Capture Pages Workflow: Capture processor context when the system is quiesced.
Event ID 159 — Capture Pages Workflow: Mark required dump data when system is quiesced.
Event ID 160 — Capture Pages Workflow: Mark important dump data when system is quiesced.
Event ID 161 — Capture Pages Workflow: Populate bitmap for dump when system is quiesced.
Description
Capture Pages Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: PopulateBitmapForDumpDuration_msms. RemoveSystemCacheFromDumpDuration RemoveSystemCacheFromDumpDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
PopulateBitmapForDumpDuration_ms UInt64 | — |
RemoveSystemCacheFromDumpDuration_ms UInt64 | — |
Event ID 162 — Capture Pages Workflow: Collect Hvl dump when system is quiesced.
Event ID 163 — Capture Pages Workflow: Generate Ipt secondary data when system is quiesced.
Event ID 164 — Capture Pages Workflow: Initiate state change to copy contents of marked pages when system is quiesced.
Event ID 165 — Capture Pages Workflow: Corral processors to quiesce the system.
Description
Capture Pages Workflow: Corral processors to quiesce the system. CorralDuration: CorralDuration_msms. DisableInterruptsDuration: DisableInterruptsDuration_msms. SaveSupervisorStateDuration: SaveSupervisorStateDuration_msms. SuspendClockTimerDuration: SuspendClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
CorralDuration_ms UInt64 | — |
DisableInterruptsDuration_ms UInt64 | — |
SaveSupervisorStateDuration_ms UInt64 | — |
SuspendClockTimerDuration_ms UInt64 | — |
Event ID 166 — Capture Pages Workflow: Uncorral processors to quiesce the system.
Description
Capture Pages Workflow: Uncorral processors to quiesce the system. UncorralDuration: UncorralDuration_msms. EnableInterruptsDuration: EnableInterruptsDuration_msms. RestoreSupervisorStateDuration: RestoreSupervisorStateDuration_msms. ResumeClockTimerDuration: ResumeClockTimerDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
UncorralDuration_ms UInt64 | — |
EnableInterruptsDuration_ms UInt64 | — |
RestoreSupervisorStateDuration_ms UInt64 | — |
ResumeClockTimerDuration_ms UInt64 | — |
Event ID 167 — Capture Pages Workflow: Capture memory pages.
Event ID 168 — Capture Pages Workflow: MmDuplicateMemory failed.
Event ID 169 — Callout for Callout (included Included).
Event ID 201 — Live Dump Write Deferred Dump Data API started.
Description
Live Dump Write Deferred Dump Data API started.
Message #
Event ID 202 — Live Dump Write Deferred Dump Data API ended.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | — |
BugcheckCode UInt32 | — |
BugCheckParameter1 Pointer | — |
BugCheckParameter2 Pointer | — |
BugCheckParameter3 Pointer | — |
BugCheckParameter4 Pointer | — |
AbortIfMemoryPressure UInt32 | — |
DumpCaptureDuration_ms UInt64 | — |
SelectiveDump UInt32 | — |
DynamicLowMemoryThresholdBytes UInt64 | — |
AvailablePhysicalMemoryInBytes UInt64 | — |
TotalPhysicalMemoryInBytes UInt64 | — |
IOSpaceEnabled Boolean | — |
Event ID 203 — Write deferred dump data to file started.
Description
Write deferred dump data to file started.
Message #
Event ID 204 — Write deferred dump data to file ended.
Description
Write deferred dump data to file ended. NT Status: NTStatus. Total TotalBytes bytes (Header|Primary|Secondary: HeaderBytes|PrimaryDataBytes|SecondaryDataBytes bytes). DumpWriteDuration: DumpWriteDuration_msms.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | — |
TotalBytes UInt64 | — |
HeaderBytes UInt64 | — |
PrimaryDataBytes UInt64 | — |
SecondaryDataBytes UInt64 | — |
DumpWriteDuration_ms UInt64 | — |
Event ID 251 — Live Dump Discard Deferred Dump Data API started.
Description
Live Dump Discard Deferred Dump Data API started.
Message #
Event ID 252 — Live Dump Discard Deferred Dump Data API ended.
Description
Live Dump Discard Deferred Dump Data API ended. NT Status: NTStatus. BugcheckCode: BugcheckCode. BugcheckParameter1: BugCheckParameter1. BugcheckParameter2: BugCheckParameter2. BugcheckParameter3: BugCheckParameter3. BugcheckParameter4: BugCheckParameter4.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus UInt32 | — |
BugcheckCode UInt32 | — |
BugCheckParameter1 Pointer | — |
BugCheckParameter2 Pointer | — |
BugCheckParameter3 Pointer | — |
BugCheckParameter4 Pointer | — |
AbortIfMemoryPressure UInt32 | — |
DumpCaptureDuration_ms UInt64 | — |
SelectiveDump UInt32 | — |
DynamicLowMemoryThresholdBytes UInt64 | — |
AvailablePhysicalMemoryInBytes UInt64 | — |
TotalPhysicalMemoryInBytes UInt64 | — |
IOSpaceEnabled Boolean | — |
Event ID 271 — AllowLiveDump policy: AllowLiveDump_policy.
Description
AllowLiveDump policy: AllowLiveDump_policy.
Message #
Fields #
| Name | Description |
|---|---|
AllowLiveDump_policy AnsiString | — |
OperationType AnsiString | — Known values
|