Microsoft-Windows-Kernel-PnP
196 events across 9 channels
Event ID 200 — Begin boot start drivers phase
Description
Begin boot start drivers phase.
Message #
Event ID 201 — End boot start drivers phase
Description
End boot start drivers phase.
Message #
Event ID 202 — Begin system start drivers phase
Description
Begin system start drivers phase.
Message #
Event ID 203 — End system start drivers phase
Description
End system start drivers phase.
Message #
Event ID 204 — OS Loader Start: OS_Loader_Start.
Description
OS Loader Start: OS_Loader_Start.
Message #
Fields #
| Name | Description |
|---|---|
OS_Loader_Start | — |
OS_Loader_End | — |
OSLoaderStart UInt64 | — |
OSLoaderEnd UInt64 | — |
PreloadEndTime UInt64 | — |
TcbLoaderStartTime UInt64 | — |
LoadHypervisorTime UInt64 | — |
LaunchHypervisorTime UInt64 | — |
LoadVsmTime UInt64 | — |
LaunchVsmTime UInt64 | — |
ExecuteTransitionStartTime UInt64 | — |
ExecuteTransitionEndTime UInt64 | — |
PerformanceDataFrequency UInt64 | — |
Event ID 205 —
Fields #
| Name | Description |
|---|---|
ElamDriverNameLength UInt16 | — |
ElamDriverName UnicodeString | — |
Event ID 206 —
Fields #
| Name | Description |
|---|---|
ElamDriverNameLength UInt16 | — |
ElamDriverName UnicodeString | — |
Event ID 207 —
Fields #
| Name | Description |
|---|---|
ElamStatus UInt32 | — |
Event ID 208 —
Fields #
| Name | Description |
|---|---|
ElamStatus UInt32 | — |
Event ID 209 —
Fields #
| Name | Description |
|---|---|
Classification UInt32 | — |
Policy UInt32 | — |
Result UInt32 | — |
Event ID 210 — Begin initializing boot start driver DriverName.
Event ID 211 — End initializing boot start driver DriverName.
Description
End initializing boot start driver DriverName. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 212 — Begin loading driver DriverName.
Event ID 213 — End loading driver DriverName.
Description
End loading driver DriverName. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ServiceNameLength UInt16 | — |
ServiceName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Version UInt32 | — |
Event ID 214 — Begin unloading driver DriverName.
Event ID 215 — End unloading driver DriverName.
Description
End unloading driver DriverName. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ServiceNameLength UInt16 | — |
ServiceName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Version UInt32 | — |
Event ID 216 — Begin starting device DriverName.
Event ID 217 — Pending start of device DriverName.
Event ID 218 — End starting device DriverName using driver FailureName.
Description
End starting device DriverName using driver FailureName. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
FailureNameLength UInt16 | — |
FailureName UnicodeString | — |
Version UInt32 | — |
Event ID 219 — The driver FailureName failed to load.
#Description
The driver FailureName failed to load.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
FailureNameLength UInt16 | — |
FailureName UnicodeString | — |
Version UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 219,
"version": 0,
"level": 3,
"task": 212,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:19.591886+00:00",
"event_record_id": 1645,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 224
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DriverNameLength": 15,
"DriverName": "ROOT\\VMBus\\0000",
"Status": 3221226341,
"FailureNameLength": 14,
"FailureName": "\\Driver\\vmbusr",
"Version": 0
},
"message": ""
}
References #
Event ID 220 — Begin querying bus relations for device DriverName.
Event ID 221 — Pending querying bus relations for device DriverName.
Event ID 222 — End querying bus relations for device DriverName.
Event ID 223 — Begin attempting to eject device DriverName.
Event ID 224 — End attempting to eject device DriverName.
Description
End attempting to eject device DriverName. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
FailureNameLength UInt16 | — |
FailureName UnicodeString | — |
Version UInt32 | — |
Event ID 225 — The application ProcessName with process id ProcessId stopped the removal or ejection for the device DeviceInstance.
Description
The application ProcessName with process id ProcessId stopped the removal or ejection for the device DeviceInstance.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
ProcessNameLength UInt16 | — |
ProcessName UnicodeString | — |
DeviceInstanceLength UInt16 | — |
DeviceInstance UnicodeString | — |
CommandLineLength UInt16 | — |
CommandLine UnicodeString | — |
VetoingDevicesLength UInt16 | — |
VetoingDevices UnicodeString | — |
Event ID 226 — Begin calling driver initialization routine for driver DriverName.
Event ID 227 — End calling driver initialization routine for driver DriverName.
Description
End calling driver initialization routine for driver DriverName. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 228 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmSid SID | — |
SqmWindowsSessionId UInt32 | — |
SqmSessionFlags UInt32 | — |
Event ID 229 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
Event ID 230 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmID UInt32 | — |
SqmDWORDDatapointValue UInt32 | — |
Event ID 231 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmID UInt32 | — |
SqmDWORDDatapointValue UInt32 | — |
Event ID 232 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmID UInt32 | — |
SqmDWORDDatapointValue UInt32 | — |
Event ID 233 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmID UInt32 | — |
SqmDWORDDatapointValue UInt32 | — |
Event ID 234 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmID UInt32 | — |
SqmDWORDDatapointValue UInt32 | — |
Event ID 235 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmID UInt32 | — |
SqmStringDatapointValue UnicodeString | — |
Event ID 236 —
Fields #
| Name | Description |
|---|---|
SqmType UInt32 | — |
SqmSessionGuid GUID | — |
SqmID UInt32 | — |
SqmStreamRowLength UInt32 | — |
SqmStreamRow Int16 | — |
Event ID 240 — A partition unit replace operation has been initiated.
Event ID 241 — A partition unit replace operation has failed.
Description
A partition unit replace operation has failed.
Message #
Fields #
| Name | Description |
|---|---|
TargetPath UnicodeString | — |
SparePath UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Location UInt32 | — |
ExtendedStatus UInt32 | — |
Event ID 242 — A partition unit has been successfully replaced.
Description
A partition unit has been successfully replaced.
Message #
Fields #
| Name | Description |
|---|---|
TargetPath UnicodeString | — |
TargetAffinity HexInt64 | — |
TargetProcessorCount UInt32 | — |
TargetMemoryCount UInt32 | — |
TargetMemorySize HexInt64 | — |
SparePath UnicodeString | — |
SpareProcessorCount UInt32 | — |
SpareMemoryCount UInt32 | — |
SpareMemorySize HexInt64 | — |
TimeTotal UInt32 | — |
TimeToQuiesce UInt32 | — |
TimeQuiesced UInt32 | — |
TimeToWake UInt32 | — |
TargetProcessors FILETIME | — |
TargetMemoryRanges SYSTEMTIME | — |
SpareProcessors HexInt32 | — |
SpareMemoryRanges HexInt64 | — |
Event ID 250 — Begin configuration of device DeviceInstance.
Event ID 251 — Pending configuration of device DeviceInstance.
Event ID 252 — End configuration of device DeviceInstance.
Description
End configuration of device DeviceInstance. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceLength UInt16 | — |
DeviceInstance UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 260 — Begin starting system start drivers part 1
Description
Begin starting system start drivers part 1.
Message #
Event ID 261 — End starting system start drivers part 1
Description
End starting system start drivers part 1.
Message #
Event ID 262 — Begin starting system start drivers part 2
Description
Begin starting system start drivers part 2.
Message #
Event ID 263 — End starting system start drivers part 2
Description
End starting system start drivers part 2.
Message #
Event ID 264 — Begin processing reinitialization requests for boot start drivers
Description
Begin processing reinitialization requests for boot start drivers.
Message #
Event ID 265 — End processing reinitialization requests for boot start drivers
Description
End processing reinitialization requests for boot start drivers.
Message #
Event ID 266 — Begin processing reinitialization requests for system start drivers
Description
Begin processing reinitialization requests for system start drivers.
Message #
Event ID 267 — End processing reinitialization requests for system start drivers
Description
End processing reinitialization requests for system start drivers.
Message #
Event ID 270 — Begin loading driver database DriverName.
Event ID 271 — Pending loading driver database DriverName.
Event ID 272 — End loading driver database DriverName.
Description
End loading driver database DriverName.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 273 — Begin unloading driver database DriverName.
Event ID 274 — Pending unloading driver database DriverName.
Event ID 275 — End unloading driver database DriverName.
Description
End unloading driver database DriverName.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 276 —
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Event ID 277 —
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 278 —
Fields #
| Name | Description |
|---|---|
BlockedDriverEntry GUID | — |
Event ID 300 — Begin starting initialization of drivers
Description
Begin starting initialization of drivers.
Message #
Event ID 301 — End starting initialization of drivers
Description
End starting initialization of drivers.
Message #
Event ID 400 — Device DeviceInstanceId was configured.
#Description
Device DeviceInstanceId was configured.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | — |
ClassGuid GUID | — |
DriverDate UnicodeString | — |
DriverVersion UnicodeString | — |
DriverProvider UnicodeString | — |
DriverInbox Boolean | — |
DriverSection UnicodeString | — |
DriverRank HexInt32 | — |
MatchingDeviceId UnicodeString | — |
OutrankedDrivers UnicodeString | — |
DeviceUpdated Boolean | — |
Status HexInt32 | — NTSTATUS reference |
ParentDeviceInstanceId UnicodeString | Parent Device. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 400,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:20:50.122130+00:00",
"event_record_id": 211,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 8
},
"channel": "Microsoft-Windows-Kernel-PnP/Configuration",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "ACPI\\GenuineIntel_-_Intel64_Family_6_Model_183_-_13th_Gen_Intel(R)_Core(TM)_i9-13980HX\\_3",
"DriverName": "cpu.inf",
"ClassGuid": "50127DC3-0F36-415E-A6CC-4CB3BE910B65",
"DriverDate": "04/21/2009",
"DriverVersion": "10.0.22621.2215",
"DriverProvider": "Microsoft",
"DriverInbox": true,
"DriverSection": "IntelPPM_Inst.NT",
"DriverRank": "0xff0004",
"MatchingDeviceId": "ACPI\\GenuineIntel_-_Intel64",
"OutrankedDrivers": "cpu.inf:ACPI\\Processor:00FF2000",
"DeviceUpdated": false,
"Status": "0x0",
"ParentDeviceInstanceId": "ACPI_HAL\\PNP0C08\\0"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 401 — Device Driver_Name failed configuration.
Description
Device Driver_Name failed configuration.
Message #
Fields #
| Name | Description |
|---|---|
Driver_Name | — |
Class_Guid | — |
Driver_Date | — |
Driver_Version | — |
Driver_Provider | — |
Driver_Section | — |
Driver_Rank | — |
Matching_Device_Id | Driver Section. |
Outranked_Drivers | Driver Rank. |
Device_Updated | Matching Device Id. |
Status HexInt32 | Outranked Drivers. NTSTATUS reference |
Parent_Device | Device Updated. |
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | — |
ClassGuid GUID | — |
DriverDate UnicodeString | — |
DriverVersion UnicodeString | — |
DriverProvider UnicodeString | — |
DriverInbox Boolean | — |
DriverSection UnicodeString | — |
DriverRank HexInt32 | — |
MatchingDeviceId UnicodeString | — |
OutrankedDrivers UnicodeString | — |
DeviceUpdated Boolean | — |
ParentDeviceInstanceId UnicodeString | — |
DriverPackageId UnicodeString | — |
Event ID 402 — Device Driver_Name had its configuration blocked by policy.
Description
Device Driver_Name had its configuration blocked by policy.
Message #
Fields #
| Name | Description |
|---|---|
Driver_Name | — |
Class_Guid | — |
Driver_Date | — |
Driver_Version | — |
Driver_Provider | — |
Driver_Section | — |
Driver_Rank | — |
Matching_Device_Id | Driver Section. |
Outranked_Drivers | Driver Rank. |
Device_Updated | Matching Device Id. |
Status HexInt32 | Outranked Drivers. NTSTATUS reference |
Parent_Device | Device Updated. |
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | — |
ClassGuid GUID | — |
DriverDate UnicodeString | — |
DriverVersion UnicodeString | — |
DriverProvider UnicodeString | — |
DriverInbox Boolean | — |
DriverSection UnicodeString | — |
DriverRank HexInt32 | — |
MatchingDeviceId UnicodeString | — |
OutrankedDrivers UnicodeString | — |
DeviceUpdated Boolean | — |
ParentDeviceInstanceId UnicodeString | — |
DriverPackageId UnicodeString | — |
Event ID 403 — Device DeviceInstanceId requires a system reboot to complete configuration.
#Description
Device DeviceInstanceId requires a system reboot to complete configuration.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | — |
ClassGuid GUID | — |
DriverDate UnicodeString | — |
DriverVersion UnicodeString | — |
DriverProvider UnicodeString | — |
DriverInbox Boolean | — |
DriverSection UnicodeString | — |
DriverRank HexInt32 | — |
MatchingDeviceId UnicodeString | — |
OutrankedDrivers UnicodeString | — |
DeviceUpdated Boolean | — |
Status HexInt32 | — NTSTATUS reference |
ParentDeviceInstanceId UnicodeString | Parent Device. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 403,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-26T04:16:19.107877+00:00",
"event_record_id": 112,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 248
},
"channel": "Microsoft-Windows-Kernel-PnP/Configuration",
"computer": "WIN-OQ6R0RVA4NF",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "ROOT\\VOLMGR\\0000",
"DriverName": "volmgr.inf",
"ClassGuid": "4D36E97D-E325-11CE-BFC1-08002BE10318",
"DriverDate": "06/21/2006",
"DriverVersion": "10.0.22621.608",
"DriverProvider": "Microsoft",
"DriverInbox": true,
"DriverSection": "Volmgr",
"DriverRank": "0xff0000",
"MatchingDeviceId": "ROOT\\VOLMGR",
"OutrankedDrivers": "",
"DeviceUpdated": false,
"Status": "0x0",
"ParentDeviceInstanceId": "HTREE\\ROOT\\0"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 410 — Device DeviceInstanceId was started.
#Description
Device DeviceInstanceId was started.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | — |
ClassGuid GUID | — |
ServiceName UnicodeString | Service. |
LowerFilters UnicodeString | — |
UpperFilters UnicodeString | — |
Problem HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 410,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:20:59.295648+00:00",
"event_record_id": 215,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 52
},
"channel": "Microsoft-Windows-Kernel-PnP/Configuration",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "ACPI\\GenuineIntel_-_Intel64_Family_6_Model_183_-_13th_Gen_Intel(R)_Core(TM)_i9-13980HX\\_3",
"DriverName": "cpu.inf",
"ClassGuid": "50127DC3-0F36-415E-A6CC-4CB3BE910B65",
"ServiceName": "intelppm",
"LowerFilters": "",
"UpperFilters": "",
"Problem": "0x0",
"Status": "0x0"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 411 — Device DeviceInstanceId had a problem starting.
#Description
Device DeviceInstanceId had a problem starting.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | — |
ClassGuid GUID | — |
ServiceName UnicodeString | Service. |
LowerFilters UnicodeString | — |
UpperFilters UnicodeString | — |
Problem HexInt32 | — |
Status HexInt32 | Problem Status. NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 411,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-26T04:17:42.366175+00:00",
"event_record_id": 168,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 52
},
"channel": "Microsoft-Windows-Kernel-PnP/Configuration",
"computer": "WIN-OQ6R0RVA4NF",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "PCI\\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\\4&bbf9765&0&0088",
"DriverName": "nete1g3e.inf",
"ClassGuid": "4D36E972-E325-11CE-BFC1-08002BE10318",
"ServiceName": "E1G60",
"LowerFilters": "",
"UpperFilters": "",
"Problem": "0x0",
"Status": "0xc00000e5"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 412 — Device Driver_Name requires a system reboot before it can be started.
Description
Device Driver_Name requires a system reboot before it can be started.
Message #
Fields #
| Name | Description |
|---|---|
Driver_Name | — |
Class_Guid | — |
Service | — |
Lower_Filters | — |
Upper_Filters | — |
Problem HexInt32 | — |
Problem_Status | — |
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | — |
ClassGuid GUID | — |
ServiceName UnicodeString | — |
LowerFilters UnicodeString | — |
UpperFilters UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 420 — Device DeviceInstanceId was deleted.
Description
Device DeviceInstanceId was deleted.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
ClassGuid GUID | — |
Problem HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
Class_Guid | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 420,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T17:24:14.944455+00:00",
"event_record_id": 226,
"correlation": {},
"execution": {
"process_id": 3668,
"thread_id": 7476
},
"channel": "Microsoft-Windows-Kernel-PnP/Configuration",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "SWD\\PRINTENUM\\{01F312F1-DACA-4AA7-96B1-5CE1A11685FD}",
"ClassGuid": "1ED2BBF9-11F0-4084-B21F-AD83A8E6DCDC",
"Problem": "0x2d",
"Status": "0x0"
},
"message": ""
}
Event ID 421 — Device Class_Guid could not be deleted.
Description
Device Class_Guid could not be deleted.
Message #
Fields #
| Name | Description |
|---|---|
Class_Guid | — |
Problem HexInt32 | — |
Status HexInt32 | — NTSTATUS reference |
DeviceInstanceId UnicodeString | — |
ClassGuid GUID | — |
Event ID 430 — Device DeviceInstanceId requires further installation.
#Description
Device DeviceInstanceId requires further installation.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 430,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-26T04:16:49.350000+00:00",
"event_record_id": 160,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 248
},
"channel": "Microsoft-Windows-Kernel-PnP/Configuration",
"computer": "WIN-OQ6R0RVA4NF",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "PCI\\VEN_8086&DEV_100F&SUBSYS_075015AD&REV_01\\4&bbf9765&0&0888"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 440 — Device settings for Last_Device_Instance_Id were migrated from previous OS installation.
Description
Device settings for Last_Device_Instance_Id were migrated from previous OS installation.
Message #
Fields #
| Name | Description |
|---|---|
Last_Device_Instance_Id | — |
Class_Guid | — |
Location_Path | — |
Migration_Rank | — |
Present Boolean | — |
DeviceInstanceId UnicodeString | — |
LastDeviceInstanceId UnicodeString | — |
ClassGuid GUID | — |
LocationPath UnicodeString | — |
MigrationRank HexInt64 | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 441 — Device settings for Last_Device_Instance_Id could not be migrated from previous OS installation.
Description
Device settings for Last_Device_Instance_Id could not be migrated from previous OS installation.
Message #
Fields #
| Name | Description |
|---|---|
Last_Device_Instance_Id | — |
Class_Guid | — |
Location_Path | — |
Migration_Rank | — |
Present Boolean | — |
Status HexInt32 | — NTSTATUS reference |
DeviceInstanceId UnicodeString | — |
LastDeviceInstanceId UnicodeString | — |
ClassGuid GUID | — |
LocationPath UnicodeString | — |
MigrationRank HexInt64 | — |
Event ID 442 — Device settings for Last_Device_Instance_Id were not migrated from previous OS installation due to partial or ambiguous device match.
Description
Device settings for Last_Device_Instance_Id were not migrated from previous OS installation due to partial or ambiguous device match.
Message #
Fields #
| Name | Description |
|---|---|
Last_Device_Instance_Id | — |
Class_Guid | — |
Location_Path | — |
Migration_Rank | — |
Present Boolean | — |
Status HexInt32 | — NTSTATUS reference |
DeviceInstanceId UnicodeString | — |
LastDeviceInstanceId UnicodeString | — |
ClassGuid GUID | — |
LocationPath UnicodeString | — |
MigrationRank HexInt64 | — |
Event ID 500 —
Fields #
| Name | Description |
|---|---|
QueryAddress Pointer | — |
ProcessId UInt32 | — |
ObjectType UnicodeString | — |
QueryType UnicodeString | — |
ObjectId UnicodeString | — |
QueryFlags UnicodeString | — |
PreferredLanguages UnicodeString | — |
RequestedProperties UnicodeString | — |
FilterExpression UnicodeString | — |
Event ID 501 —
Fields #
| Name | Description |
|---|---|
QueryAddress Pointer | — |
Event ID 502 —
Fields #
| Name | Description |
|---|---|
QueryAddress Pointer | — |
Event ID 503 —
Fields #
| Name | Description |
|---|---|
QueryAddress Pointer | — |
Event ID 600 — A start type override of StartType was set for driver Driver in hardware configuration HardwareConfigurationId.
Event ID 700 —
Fields #
| Name | Description |
|---|---|
Filter UnicodeString | — |
FilterBy UnicodeString | — |
OnlyPresent Boolean | — |
Event ID 701 —
Fields #
| Name | Description |
|---|---|
Result HexInt32 | — |
Event ID 702 —
Fields #
| Name | Description |
|---|---|
Class GUID | — |
Device UnicodeString | — |
OnlyPresent Boolean | — |
Event ID 703 —
Fields #
| Name | Description |
|---|---|
Result HexInt32 | — |
Event ID 704 —
Fields #
| Name | Description |
|---|---|
QueryRemoveType HexInt32 | — |
Device UnicodeString | — |
Event ID 705 —
Fields #
| Name | Description |
|---|---|
Device UnicodeString | — |
Event ID 800 — Begin processing new device (DeviceNode).
Event ID 801 — Processing device DeviceInstancePath (DeviceNode).
Event ID 802 — End processing new device (DeviceNode).
Event ID 803 — Begin processing phase Phase of starting device Device.
Event ID 804 — End processing phase Phase of starting device Device.
Event ID 805 — Begin processing phase Phase of restarting device Device.
Event ID 806 — End processing phase Phase of restarting device Device.
Event ID 807 — Begin device add operation for driver DriverName, device DeviceInstancePath.
Description
Begin device add operation for driver DriverName, device DeviceInstancePath.
Message #
Fields #
| Name | Description |
|---|---|
ServiceType UInt32 | — Known values
|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
DeviceInstancePath UnicodeString | — |
Event ID 808 — End device add, status (Status).
Description
End device add, status (Status).
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 809 — Duplicate device instance reported by BusId and DeviceId.
Event ID 810 — Reenumeration of device tree below Device has been queued.
Event ID 811 — Begin reenumeration of device tree below Device.
Event ID 812 — End reenumeration of device tree below Device.
Event ID 813 — Reenumeration of Device has been queued.
Event ID 814 — Begin reenumeration of Device.
Event ID 815 — End reenumeration of Device.
Event ID 816 — Configuration of device Device for configuration type RequestType has been queued.
Event ID 817 — Begin configuration of device Device for configuration type RequestType.
Event ID 818 — End configuration of device Device for configuration type RequestType.
Description
End configuration of device Device for configuration type RequestType. Result is Status.
Message #
Fields #
| Name | Description |
|---|---|
Device UnicodeString | — |
RequestType HexInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 819 —
Fields #
| Name | Description |
|---|---|
Device UnicodeString | — |
RequestType HexInt32 | — |
Event ID 820 —
Fields #
| Name | Description |
|---|---|
Device UnicodeString | — |
RequestType HexInt32 | — |
Event ID 821 —
Fields #
| Name | Description |
|---|---|
Device UnicodeString | — |
RequestType HexInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 830 — Removal of Device has been queued.
Event ID 831 — Begin removal of Device.
Event ID 832 — End removal of Device.
Event ID 840 — Begin resetting device DeviceInstance.
Event ID 841 — End resetting device DeviceInstance with status Status, veto type VetoType, veto name VetoName.
Description
End resetting device DeviceInstance with status Status, veto type VetoType, veto name VetoName.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceLength UInt16 | — |
DeviceInstance UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
VetoType UInt32 | — |
VetoNameLength UInt16 | — |
VetoName UnicodeString | — |
Event ID 850 — Begin assigning resources to device tree below Device.
Event ID 851 — End assigning resources to device tree below Device.
Event ID 852 — Begin rebalancing resources for device DeviceInstance.
Event ID 853 — End rebalancing resources for device DeviceInstance.
Description
End rebalancing resources for device DeviceInstance.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceLength UInt16 | — |
DeviceInstance UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 860 — Updated problem code on device DeviceInstanceId.
Event ID 900 — A long running thread for the device event queue was detected.
Description
A long running thread for the device event queue was detected. The thread has been running for ThreadId milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
Thread_ID | — |
Device | — |
Service | — |
ThreadId HexInt64 | — |
DeviceInstanceId UnicodeString | — |
ServiceName UnicodeString | — |
ElapsedTimeMs UInt64 | — |
EventCategory UInt32 | — |
EventGuid GUID | — |
EventArgument HexInt32 | — |
EventArgumentStatus HexInt32 | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Event ID 901 — A long running thread for the device event queue has been completed.
Description
A long running thread for the device event queue has been completed.
Message #
Fields #
| Name | Description |
|---|---|
ThreadId HexInt64 | — |
DeviceInstanceId UnicodeString | — |
ServiceName UnicodeString | — |
ElapsedTimeMs UInt64 | — |
EventCategory UInt32 | — |
EventGuid GUID | — |
EventArgument HexInt32 | — |
EventArgumentStatus HexInt32 | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Event ID 902 — A long running thread for device start processing was detected.
Event ID 903 — A long running thread for device start processing has been completed.
Event ID 904 — A long running thread for device removal was detected.
Event ID 905 — A long running thread for device removal has been completed.
Event ID 906 — A long running thread for device add routine was detected.
Event ID 907 — A long running thread for device add routine has been completed.
Event ID 908 — A long running thread for driver entry was detected.
#Description
A long running thread for driver entry was detected. The thread has been running for ElapsedTimeMs milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
ThreadId HexInt64 | — |
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | Driver. |
ElapsedTimeMs UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 908,
"version": 0,
"level": 3,
"task": 900,
"opcode": 1,
"keywords": 144115188075855872,
"time_created": "2023-11-06T00:25:57.930157+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 2352
},
"channel": "Microsoft-Windows-Kernel-PnP/Driver Watchdog",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ThreadId": "0x2ba4",
"DeviceInstanceId": "",
"DriverName": "avgSP",
"ElapsedTimeMs": 10005
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 909 — A long running thread for driver entry routine has been completed.
#Description
A long running thread for driver entry routine has been completed.
Message #
Fields #
| Name | Description |
|---|---|
ThreadId HexInt64 | — |
DeviceInstanceId UnicodeString | — |
DriverName UnicodeString | Driver. |
ElapsedTimeMs UInt64 | Total run time in milliseconds. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 909,
"version": 0,
"level": 4,
"task": 900,
"opcode": 2,
"keywords": 144115188075855872,
"time_created": "2023-11-06T00:26:29.468233+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 11172
},
"channel": "Microsoft-Windows-Kernel-PnP/Driver Watchdog",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ThreadId": "0x2ba4",
"DeviceInstanceId": "",
"DriverName": "avgSP",
"ElapsedTimeMs": 41546
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 930 — Timed out waiting for response from user mode clients to synchronous notification EventGuid.
Event ID 931 — Responses from user mode clients to synchronous notification EventGuid took TimeMs milliseconds.
Event ID 932 — Synchronous notification EventGuid to process ProcessId (ProcessImageName) was removed after ElapsedTimeMs milliseconds.
Description
Synchronous notification EventGuid to process ProcessId (ProcessImageName) was removed after ElapsedTimeMs milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
FilterType UInt32 | — |
ProcessId UInt32 | — |
ProcessImageName UnicodeString | — |
QueueDepth UInt32 | — |
DropCount UInt32 | — |
RegistrationTeardown Boolean | — |
EventGuid GUID | — |
EventCategory UInt32 | — |
DeviceInstanceId UnicodeString | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Synchronous Boolean | — |
NotificationReceivedByClient Boolean | — |
ElapsedTimeMs UInt64 | — |
Event ID 933 — Notification EventGuid to driver DriverName took ElapsedTimeMs milliseconds.
Description
Notification EventGuid to driver DriverName took ElapsedTimeMs milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
EventCategory UInt32 | — |
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
EventGuid GUID | — |
ElapsedTimeMs UInt64 | — |
NotificationSpecific_Guid GUID | — |
UnicodeStringLength UInt16 | — |
NotificationSpecific_UnicodeString UnicodeString | — |
Event ID 1000 — Device DeviceInstanceId could not be query removed as the removal was vetoed.
#Description
Device DeviceInstanceId could not be query removed as the removal was vetoed.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
VetoType UInt32 | — |
VetoName UnicodeString | Vetoed By. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 72057594037927936,
"time_created": "2023-10-25T22:50:39.854895+00:00",
"event_record_id": 10,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 384
},
"channel": "Microsoft-Windows-Kernel-PnP/Device Management",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "ACPI\\PNP0303\\4&1bd7f811&0",
"VetoType": 6,
"VetoName": "ACPI\\PNP0303\\4&1bd7f811&0\\Driver\\i8042prt"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1010 — Device DeviceInstanceId has been surprise removed as it is reported as missing on the bus.
#Description
Device DeviceInstanceId has been surprise removed as it is reported as missing on the bus.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
DeviceCount UInt32 | Count of devices removed. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Kernel-PnP",
"guid": "9C205A39-1250-487D-ABD7-E831C6290539",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 72057594037927936,
"time_created": "2023-11-06T01:46:52.163431+00:00",
"event_record_id": 23,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 17804
},
"channel": "Microsoft-Windows-Kernel-PnP/Device Management",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceInstanceId": "SWD\\MSDAS\\{ce958e9a-424f-4c88-86f4-11314821e75a}",
"DeviceCount": 1
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1011 — Device DeviceInstanceId has been surprise removed as it was reported to be failing.
Event ID 1020 — A resource rebalance operation has succeeded.
Description
A resource rebalance operation has succeeded.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
ServiceName UnicodeString | — |
DeviceCount UInt32 | — |
Phase UInt32 | — |
SubtreeRootInstanceId UnicodeString | — |
SubtreeIncludesRoot Boolean | — |
RebalanceDueToDynamicPartitioning Boolean | — |
RebalanceReason UInt32 | — |
ConflictResourceType UInt8 | — |
DurationInMs UInt64 | — |
ResetDeviceWhileStopped Boolean | — |
Event ID 1021 — A resource rebalance operation has failed.
Description
A resource rebalance operation has failed.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstanceId UnicodeString | — |
ServiceName UnicodeString | — |
DeviceCount UInt32 | — |
Phase UInt32 | — |
SubtreeRootInstanceId UnicodeString | — |
SubtreeIncludesRoot Boolean | — |
RebalanceDueToDynamicPartitioning Boolean | — |
RebalanceReason UInt32 | — |
ConflictResourceType UInt8 | — |
RebalanceFailure UInt32 | — |
VetoReason UInt32 | — |
VetoNodeInstanceId UnicodeString | — |
DurationInMs UInt64 | — |
ResetDeviceWhileStopped Boolean | — |
Event ID 1030 — Device Device has been assigned to a guest partition.
Event ID 1031 — Device Device is no longer assigned to a guest partition.
Event ID 1040 — Device Flags has requested a platform-level device reset.
Event ID 1041 — Device Veto_type has completed a platform-level device reset.
Description
Device Veto_type has completed a platform-level device reset.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Veto_type | — |
Vetoed_By | Status. |
DeviceInstanceLength UInt16 | — |
DeviceInstance UnicodeString | — |
VetoType UInt32 | — |
VetoNameLength UInt16 | — |
VetoName UnicodeString | — |
Event ID 1050 — Failed to create driver package defined child device of Child_Instance_ID.
Description
Failed to create driver package defined child device of Child_Instance_ID.
Message #
Fields #
| Name | Description |
|---|---|
Child_Instance_ID | — |
Status HexInt32 | — NTSTATUS reference |
ParentDeviceInstancePath UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1060 — Failed to create computer device derived from firmware information.
Description
Failed to create computer device derived from firmware information. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | — NTSTATUS reference |
Event ID 1065 — Device DeviceInstanceId with problem code ProblemCode and problem status ProblemStatus requires the system to be rebooted.
Event ID 1070 — Failed to open DeviceStackLocation driver service ServiceName for device DeviceInstance.
Description
Failed to open DeviceStackLocation driver service ServiceName for device DeviceInstance. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
DeviceInstance UnicodeString | — |
ServiceName UnicodeString | — |
DeviceStackLocation UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1080 — The driver FailureName failed to unload.
Description
The driver FailureName failed to unload.
Message #
Fields #
| Name | Description |
|---|---|
DriverNameLength UInt16 | — |
DriverName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
FailureNameLength UInt16 | — |
FailureName UnicodeString | — |
Version UInt32 | — |
Event ID 1100 —
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1100
Event ID 1101 —
Fields #
| Name | Description |
|---|---|
Status HexInt32 | — NTSTATUS reference |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1101
Event ID 1102 —
Fields #
| Name | Description |
|---|---|
EnumeratorName UnicodeString | — |
InstanceId UnicodeString | — |
ParentDeviceInstanceId UnicodeString | — |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1102
Event ID 1103 —
Fields #
| Name | Description |
|---|---|
EnumeratorName UnicodeString | — |
InstanceId UnicodeString | — |
ParentDeviceInstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1104 —
Fields #
| Name | Description |
|---|---|
EnumeratorName UnicodeString | — |
InstanceId UnicodeString | — |
ParentDeviceInstanceId UnicodeString | — |
CapabilityFlags HexInt32 | — |
DeviceDescription UnicodeString | — |
DeviceLocation UnicodeString | — |
NumProperties UInt32 | — |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1104
Event ID 1105 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1105
Event ID 1106 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1107 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
RemovedFromBus Boolean | — |
HasPrimaryDeviceObject Boolean | — |
Event ID 1108 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
AlreadyExists Boolean | — |
References #
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1108
Event ID 1109 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1110 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
DeviceInstancePath UnicodeString | — |
Event ID 1111 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1120 —
Event ID 1121 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
ParentDeviceInstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
References #
Event ID 1122 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
ParentDeviceInstanceId UnicodeString | — |
Event ID 1130 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1131 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1132 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
OldLifetime UInt32 | — |
NewLifetime UInt32 | — |
Event ID 1140 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1141 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1142 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
SymbolicLink UnicodeString | — |
Event ID 1143 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
SymbolicLink UnicodeString | — |
Enable Boolean | — |
Event ID 1144 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1145 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1150 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1151 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1160 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1161 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1170 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1171 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
DeviceClosed Boolean | — |
Event ID 1172 —
Fields #
| Name | Description |
|---|---|
ParentDeviceInstanceId UnicodeString | — |
EnumeratorName UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1173 —
Fields #
| Name | Description |
|---|---|
ParentDeviceInstanceId UnicodeString | — |
EnumeratorName UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1174 —
Fields #
| Name | Description |
|---|---|
ParentDeviceInstanceId UnicodeString | — |
Event ID 1175 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1176 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
DeviceInstanceId UnicodeString | — |
KeepActive Boolean | — |
SwDeviceFlags HexInt32 | — |
DeviceExtensionFlags HexInt32 | — |
Event ID 1177 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
DeviceInstanceId UnicodeString | — |
ParentDeviceInstanceId UnicodeString | — |
SwDeviceFlags HexInt32 | — |
DeviceExtensionFlags HexInt32 | — |
Event ID 1178 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
DeviceInstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1190 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
ParentDeviceInstanceId UnicodeString | — |
SwDeviceFlags HexInt32 | — |
Event ID 1191 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
PdoReported Boolean | — |
NewPdo Boolean | — |
Event ID 1192 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
SkipCount UInt32 | — |
Event ID 1200 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Event ID 1201 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1202 —
Fields #
| Name | Description |
|---|---|
DeviceId UnicodeString | — |
InstanceId UnicodeString | — |
OldAttributes UInt32 | — |
NewAttributes UInt32 | — |
Event ID 1300 —
Fields #
| Name | Description |
|---|---|
FilterType UInt32 | — |
ProcessId UInt32 | — |
ProcessImageName UnicodeString | — |
QueueDepth UInt32 | — |
DropCount UInt32 | — |
EventGuid GUID | — |
EventCategory UInt32 | — |
DeviceInstanceId UnicodeString | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Synchronous Boolean | — |
ElapsedTimeMs UInt64 | — |
Event ID 1301 —
Fields #
| Name | Description |
|---|---|
FilterType UInt32 | — |
ProcessId UInt32 | — |
ProcessImageName UnicodeString | — |
QueueDepth UInt32 | — |
DropCount UInt32 | — |
EventGuid GUID | — |
EventCategory UInt32 | — |
DeviceInstanceId UnicodeString | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Synchronous Boolean | — |
ElapsedTimeMs UInt64 | — |
Event ID 1302 —
Fields #
| Name | Description |
|---|---|
FilterType UInt32 | — |
ProcessId UInt32 | — |
ProcessImageName UnicodeString | — |
QueueDepth UInt32 | — |
DropCount UInt32 | — |
EventGuid GUID | — |
EventCategory UInt32 | — |
DeviceInstanceId UnicodeString | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Synchronous Boolean | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1303 —
Fields #
| Name | Description |
|---|---|
FilterType UInt32 | — |
ProcessId UInt32 | — |
ProcessImageName UnicodeString | — |
QueueDepth UInt32 | — |
DropCount UInt32 | — |
EventGuid GUID | — |
EventCategory UInt32 | — |
DeviceInstanceId UnicodeString | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Synchronous Boolean | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 1304 —
Fields #
| Name | Description |
|---|---|
FilterType UInt32 | — |
ProcessId UInt32 | — |
ProcessImageName UnicodeString | — |
QueueDepth UInt32 | — |
DropCount UInt32 | — |
RegistrationTeardown Boolean | — |
EventGuid GUID | — |
EventCategory UInt32 | — |
DeviceInstanceId UnicodeString | — |
CategorySpecificData_Guid GUID | — |
CategorySpecificData_String UnicodeString | — |
Synchronous Boolean | — |
NotificationReceivedByClient Boolean | — |
ElapsedTimeMs UInt64 | — |
Event ID 1400 — Begin serializing boot with PnP device enumeration
Description
Begin serializing boot with PnP device enumeration.
Message #
Event ID 1401 — End serializing boot with PnP device enumeration
Description
End serializing boot with PnP device enumeration.