Microsoft-Windows-Kernel-Power
353 events across 5 channels
Event ID 1 —
Fields
| Name | Description |
|---|---|
Reason | — |
Flags | — |
Time | — |
Event ID 2 —
Fields
| Name | Description |
|---|---|
Status | — |
Time | — |
WakeSourceTypeLength | — |
WakeSourceSubTypeLength | — |
WakeSourceLength | — |
WakeSourceContextLength | — |
WakeSourceType | — |
WakeSourceSubType | — |
WakeSource | — |
WakeSourceContext | — |
Event ID 3 —
Event ID 4 —
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 5 —
Event ID 6 —
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 7 —
Fields
| Name | Description |
|---|---|
Irp | — |
PowerStateType | — |
MinorFunction | — |
TargetDevice | — |
InstanceNameLength | — |
InstanceName | — |
PowerState | — |
Event ID 8 —
Fields
| Name | Description |
|---|---|
Irp | — |
Status | — |
FailedDriver | — |
Event ID 9 — The application %4 stopped the power transition.
Message
Fields
| Name | Description |
|---|---|
Pid | — |
Window | — |
AppNameLength | — |
AppName | — |
Event ID 10 — The service %3 stopped the power transition.
Message
Fields
| Name | Description |
|---|---|
Pid | — |
ServiceNameLength | — |
ServiceName | — |
Event ID 11 —
Fields
| Name | Description |
|---|---|
Irp | — |
Event ID 12 —
Fields
| Name | Description |
|---|---|
Pid | — |
NameLength | — |
Name | — |
Event ID 13 —
Fields
| Name | Description |
|---|---|
Pid | — |
Event ID 14 —
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
Event ID 15 —
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
Event ID 16 —
Fields
| Name | Description |
|---|---|
Pid | — |
NameLength | — |
Name | — |
Event ID 17 —
Fields
| Name | Description |
|---|---|
Pid | — |
Event ID 18 —
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
Event ID 19 —
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
Event ID 20 —
Fields
| Name | Description |
|---|---|
Irp | — |
Device | — |
DriverName | — |
Event ID 21 —
Fields
| Name | Description |
|---|---|
Irp | — |
Device | — |
Event ID 22 —
Event ID 23 —
Event ID 24 —
Event ID 25 —
Event ID 26 —
Event ID 27 —
Event ID 28 —
Fields
| Name | Description |
|---|---|
Pid | — |
NameLength | — |
Name | — |
Event ID 29 —
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
Event ID 30 —
Event ID 31 —
Event ID 32 —
Fields
| Name | Description |
|---|---|
Pid | — |
NameLength | — |
Name | — |
Event ID 33 —
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
Event ID 34 —
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 35 —
Fields
| Name | Description |
|---|---|
Query | — |
TargetState | — |
EffectiveState | — |
Event ID 36 —
Event ID 37 —
Event ID 38 —
Event ID 39 —
Fields
| Name | Description |
|---|---|
SleepTime | — |
ResumeTime | — |
DriverWakeTime | — |
HiberWriteTime | — |
HiberReadTime | — |
HiberPagesWritten | — |
BiosInitTime | — |
CheckpointTime | — |
Event ID 40 — The driver %2 for device %4 stopped the power transition.
Message
Fields
| Name | Description |
|---|---|
DriverNameLength | — |
DriverName | — |
InstanceNameLength | — |
InstanceName | — |
Event ID 41 — The last sleep transition was unsuccessful.
Message
Fields
| Name | Description |
|---|---|
BugcheckCode | — |
BugcheckParameter1 | — |
BugcheckParameter2 | — |
BugcheckParameter3 | — |
BugcheckParameter4 | — |
SleepInProgress | — |
PowerButtonTimestamp | — |
BootAppStatus | — |
Checkpoint | — |
ConnectedStandbyInProgress | — |
SystemSleepTransitionsToOn | — |
CsEntryScenarioInstanceId | — |
BugcheckInfoFromEFI | — |
CheckpointStatus | — |
CsEntryScenarioInstanceIdV2 | — |
LongPowerButtonPressDetected | — |
LidReliability | — |
InputSuppressionState | — |
PowerButtonSuppressionState | — |
LidState | — |
WHEABootErrorCount | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-Power
guid: 331C3B3A-2005-44C2-AC5E-77220C37D6B4
event_source_name: ''
event_id: 41
version: 2
level: 1
task: 63
opcode: 0
keywords: 9223372036854775810
time_created: '2012-04-06T19:11:29.968750Z'
event_record_id: 13534
correlation: {}
execution:
process_id: 4
thread_id: 8
channel: System
computer: WKS-WIN764BITB.shieldbase.local
security:
user_id: S-1-5-18
event_data:
BugcheckCode: 0
BugcheckParameter1: '0x0'
BugcheckParameter2: '0x0'
BugcheckParameter3: '0x0'
BugcheckParameter4: '0x0'
SleepInProgress: false
PowerButtonTimestamp: 0
Event ID 42 — The system is entering sleep.
Message
Fields
| Name | Description |
|---|---|
TargetState | — |
EffectiveState | — |
Reason | — |
Flags | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-Power
guid: 331C3B3A-2005-44C2-AC5E-77220C37D6B4
event_source_name: ''
event_id: 42
version: 2
level: 4
task: 64
opcode: 0
keywords: 9223372036854775812
time_created: '2016-08-18T16:22:13.389648Z'
event_record_id: 5523
correlation: {}
execution:
process_id: 4
thread_id: 60
channel: System
computer: IE10Win7
security:
user_id: ''
event_data:
TargetState: 2
EffectiveState: 2
Reason: 7
Flags: 0
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 43 —
Event ID 44 —
Event ID 45 —
Event ID 46 —
Event ID 47 —
Event ID 48 —
Event ID 49 —
Event ID 50 —
Event ID 51 —
Event ID 52 —
Event ID 53 —
Event ID 54 —
Event ID 55 —
Event ID 56 —
Event ID 57 —
Event ID 58 —
Event ID 59 — The system is entering Away Mode.
Message
Event ID 60 —
Fields
| Name | Description |
|---|---|
Value | — |
Event ID 61 —
Fields
| Name | Description |
|---|---|
Value | — |
Event ID 62 — The application or service %3 has overridden user power management settings with a code of %1.
Message
Fields
| Name | Description |
|---|---|
ExecutionState | — |
AppNameLength | — |
AppName | — |
Pid | — |
Tid | — |
EffectiveExecutionState | — |
IgnoreReason | — |
Event ID 63 — The application or service %3 is attempting to update the system timer resolution to a value of %1.
Message
Fields
| Name | Description |
|---|---|
RequestedResolution | — |
Pid | — |
AppNameLength | — |
AppName | — |
SubProcessTag | — |
RequestIgnored | — |
Event ID 64 —
Event ID 65 —
Event ID 66 —
Event ID 67 —
Event ID 68 —
Event ID 69 —
Event ID 70 —
Event ID 71 —
Event ID 72 —
Fields
| Name | Description |
|---|---|
Threshold | — |
LowestIdleness | — |
AverageIdleness | — |
AccruedIdleTime | — |
NonIdleIgnored | — |
IdleToSleep | — |
NonIdleReferences | — |
Event ID 73 —
Fields
| Name | Description |
|---|---|
ExecutionState | — |
MonitorReason | — |
Event ID 74 —
Fields
| Name | Description |
|---|---|
ExecutionState | — |
StateHandle | — |
Event ID 75 —
Event ID 76 —
Event ID 77 —
Fields
| Name | Description |
|---|---|
Device | — |
Pdo | — |
InstancePathLength | — |
InstancePath | — |
ConservativeTimeout | — |
PerformanceTimeout | — |
IdleTime | — |
BusyCount | — |
TotalBusyCount | — |
IdlePowerState | — |
CurrentPowerState | — |
Event ID 78 —
Fields
| Name | Description |
|---|---|
Device | — |
Timeout | — |
IgnoreThreshold | — |
IdleTime | — |
NonIdleTime | — |
Event ID 79 — Timer tick distribution policy: Disabled: %1 Overridden: %2.
Message
Fields
| Name | Description |
|---|---|
Disabled | [Timer tick distribution policy] Disabled. |
Overridden | [Timer tick distribution policy] Overridden. |
Event ID 80 — ACPI thermal zone %2 has changed to %4 cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
CoolingModeLength | — |
CoolingMode | — |
Event ID 81 — ACPI thermal zone %2 has %5 passive cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
PassiveCoolingStateLength | — |
PassiveCoolingState | — |
AffinityCount | — |
_PSV | — |
_TMP | — |
_TC1 | — |
_TC2 | — |
_TSP | — |
DeltaP | — |
_PSL | — |
Event ID 82 — ACPI thermal zone %2 has %5 passive cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
PassiveCoolingStateLength | — |
PassiveCoolingState | — |
AffinityCount | — |
_PSV | — |
_TMP | — |
_TC1 | — |
_TC2 | — |
_TSP | — |
DeltaP | — |
_PSL | — |
Event ID 83 — ACPI thermal zone %2 has %5 active cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
ActiveCoolingStateLength | — |
ActiveCoolingState | — |
_AC0 | — |
_AC1 | — |
_AC2 | — |
_AC3 | — |
_AC4 | — |
_AC5 | — |
_AC6 | — |
_AC7 | — |
_AC8 | — |
_AC9 | — |
_TMP | — |
Event ID 84 — ACPI thermal zone %2 has %5 active cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
ActiveCoolingStateLength | — |
ActiveCoolingState | — |
_AC0 | — |
_AC1 | — |
_AC2 | — |
_AC3 | — |
_AC4 | — |
_AC5 | — |
_AC6 | — |
_AC7 | — |
_AC8 | — |
_AC9 | — |
_TMP | — |
Event ID 85 — The system was shut down due to a critical thermal event.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
ShutdownTime | — |
_CRT | — |
Event ID 86 — The system was shut down due to a critical thermal event.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
ShutdownTime | — |
_CRT | — |
Event ID 87 — The system was hibernated due to a critical thermal event.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
HibernateTime | — |
_HOT | — |
Event ID 88 — The system was hibernated due to a critical thermal event.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
HibernateTime | — |
_HOT | — |
Event ID 89 — ACPI thermal zone %2 has been enumerated.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
AffinityCount | — |
_PSV | — |
_TC1 | — |
_TC2 | — |
_TSP | — |
_AC0 | — |
_AC1 | — |
_AC2 | — |
_AC3 | — |
_AC4 | — |
_AC5 | — |
_AC6 | — |
_AC7 | — |
_AC8 | — |
_AC9 | — |
_CRT | — |
_HOT | — |
_PSL | — |
Event ID 90 — Processor %1 was throttled by an entity other than the kernel power manager.
Message
Fields
| Name | Description |
|---|---|
ProcessorId | — |
ThrottleMSR | — |
ElapsedTime | — |
LogInterval | — |
Event ID 91 — Processor %1 was throttled by an entity other than the kernel power manager.
Message
Fields
| Name | Description |
|---|---|
ProcessorId | — |
ThrottleMSR | — |
ElapsedTime | — |
LogInterval | — |
Event ID 92 —
Fields
| Name | Description |
|---|---|
Token | — |
Type | — |
ProcessID | — |
SessionID | — |
Legacy | — |
SystemAllowed | — |
DisplayAllowed | — |
AwayModeAllowed | — |
SystemCount | — |
DisplayCount | — |
AwayModeCount | — |
CallerLength | — |
ContextLength | — |
Caller | — |
Context | — |
ExecutionRequiredAllowed | — |
PerformanceBoostAllowed | — |
FullScreenVideoAllowed | — |
ExecutionRequiredCount | — |
PerformanceBoostCount | — |
FullScreenVideoCount | — |
Event ID 93 —
Fields
| Name | Description |
|---|---|
Token | — |
SystemCount | — |
DisplayCount | — |
AwayModeCount | — |
ExecutionRequiredCount | — |
PerformanceBoostCount | — |
FullScreenVideoCount | — |
Event ID 94 —
Fields
| Name | Description |
|---|---|
Token | — |
Event ID 95 — The system timer resolution has changed to a value of %1.
Message
Fields
| Name | Description |
|---|---|
NewResolution | — |
Event ID 96 — The system timer resolution currently has a value of %1.
Message
Fields
| Name | Description |
|---|---|
CurrentPeriod | — |
MinimumPeriod | — |
MaximumPeriod | — |
KernelRequestCount | — |
KernelRequestedPeriod | — |
InternalSetPeriod | — |
Event ID 97 — The system timer resolution currently has a value of %1.
Message
Fields
| Name | Description |
|---|---|
RequestedPeriod | — |
Pid | — |
AppNameLength | — |
AppName | — |
RequestIgnored | — |
Event ID 98 — A driver is attempting to update the system timer resolution to a value of %1.
Message
Fields
| Name | Description |
|---|---|
RequestedResolution | — |
Tag | — |
Event ID 99 —
Fields
| Name | Description |
|---|---|
Token | — |
Type | — |
ProcessID | — |
SessionID | — |
Legacy | — |
SystemAllowed | — |
DisplayAllowed | — |
AwayModeAllowed | — |
SystemCount | — |
DisplayCount | — |
AwayModeCount | — |
CallerLength | — |
ContextLength | — |
Caller | — |
Context | — |
ExecutionRequiredAllowed | — |
PerformanceBoostAllowed | — |
FullScreenVideoAllowed | — |
ExecutionRequiredCount | — |
PerformanceBoostCount | — |
FullScreenVideoCount | — |
Event ID 100 —
Event ID 101 —
Event ID 102 —
Event ID 103 —
Event ID 104 —
Fields
| Name | Description |
|---|---|
AffectedState | — |
PowerReasonCode | — |
PowerReasonLength | — |
PowerReasonInfo | — |
Event ID 105 — Power source change.
Message
Fields
| Name | Description |
|---|---|
AcOnline | — |
RemainingCapacity | — |
FullChargeCapacity | — |
Event ID 106 —
Fields
| Name | Description |
|---|---|
AcOnline | — |
Event ID 107 —
Fields
| Name | Description |
|---|---|
TargetState | — |
EffectiveState | — |
WakeFromState | — |
Event ID 107 — The system has resumed from sleep.
Message
Fields
| Name | Description |
|---|---|
TargetState | — |
EffectiveState | — |
WakeFromState | — |
ProgrammedWakeTimeAc | — |
ProgrammedWakeTimeDc | — |
WakeRequesterTypeAc | — |
WakeRequesterTypeDc | — |
Event ID 108 —
Fields
| Name | Description |
|---|---|
CopyBytes | — |
ElapsedTime | — |
IoTime | — |
InitTime | — |
CopyTime | — |
PagesWritten | — |
PagesProcessed | — |
DumpCount | — |
FileRuns | — |
ReadTime | — |
ResumeAppTime | — |
CompressTime | — |
Event ID 109 — The kernel power manager has initiated a shutdown transition.
Message
Fields
| Name | Description |
|---|---|
ShutdownActionType | Action. |
ShutdownEventCode | Event Code. |
ShutdownReason | Reason. |
Example Event
system:
provider: Microsoft-Windows-Kernel-Power
guid: 331C3B3A-2005-44C2-AC5E-77220C37D6B4
event_source_name: ''
event_id: 109
version: 0
level: 4
task: 103
opcode: 0
keywords: 9223442405598954500
time_created: '2023-11-06T06:23:40.686261+00:00'
event_record_id: 1621
correlation: {}
execution:
process_id: 680
thread_id: 684
channel: System
computer: WinDev2310Eval
security:
user_id: ''
event_data:
ShutdownActionType: 5
ShutdownEventCode: 0
ShutdownReason: 5
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 110 —
Fields
| Name | Description |
|---|---|
RequestedPeriod | — |
Pid | — |
AppNameLength | — |
AppName | — |
StackSize | — |
Stack | — |
Event ID 111 —
Fields
| Name | Description |
|---|---|
SettingGuid | — |
DataSize | — |
Data | — |
Override | — |
Event ID 112 —
Fields
| Name | Description |
|---|---|
SettingGuid | — |
DataSize | — |
Data | — |
Override | — |
Event ID 113 — ACPI thermal zone %2 has %4 passive cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
PassiveCoolingState | — |
_PSV | — |
_TMP | — |
_TC1 | — |
_TC2 | — |
_TSP | — |
DeltaP | — |
MinimumThrottle | — |
Event ID 114 — ACPI thermal zone %2 has %4 passive cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
PassiveCoolingState | — |
_PSV | — |
_TMP | — |
_TC1 | — |
_TC2 | — |
_TSP | — |
DeltaP | — |
MinimumThrottle | — |
Event ID 115 — ACPI thermal zone %2 has %4 active cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
ActiveCoolingState | — |
_AC0 | — |
_AC1 | — |
_AC2 | — |
_AC3 | — |
_AC4 | — |
_AC5 | — |
_AC6 | — |
_AC7 | — |
_AC8 | — |
_AC9 | — |
_TMP | — |
Event ID 116 — ACPI thermal zone %2 has %4 active cooling.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
EventTime | — |
ActiveCoolingState | — |
_AC0 | — |
_AC1 | — |
_AC2 | — |
_AC3 | — |
_AC4 | — |
_AC5 | — |
_AC6 | — |
_AC7 | — |
_AC8 | — |
_AC9 | — |
_TMP | — |
Event ID 117 —
Fields
| Name | Description |
|---|---|
TotalResumeTime | — |
POSTTime | — |
ResumeBootMgrTime | — |
ResumeAppTime | — |
ResumeAppStartTime | — |
ResumeLibraryInitTime | — |
ResumeInitTime | — |
ResumeHiberFileTime | — |
ResumeRestoreImageStartTimestamp | — |
ResumeIoTime | — |
ResumeDecompressTime | — |
ResumeMapTime | — |
ResumeUnmapTime | — |
ResumeUserInOutTime | — |
ResumeAllocateTime | — |
ResumeKernelSwitchTimestamp | — |
KernelReturnFromHandlerTimestamp | — |
SleeperThreadEndTimestamp | — |
TimeStampCounterAtSwitchTime | — |
KernelReturnSystemPowerStateTimestamp | — |
HiberHiberFileTime | — |
InitTime | — |
HiberSharedBufferTime | — |
TotalHibernateTime | — |
KernelResumeHiberFileTime | — |
KernelResumeInitTime | — |
KernelResumeSharedBufferTime | — |
DeviceResumeTime | — |
KernelAnimationTime | — |
KernelPagesProcessed | — |
KernelPagesWritten | — |
BootPagesProcessed | — |
BootPagesWritten | — |
HiberWriteRate | — |
HiberCompressRate | — |
ResumeReadRate | — |
ResumeDecompressRate | — |
FileRuns | — |
NoMultiStageResumeReason | — |
MaxHuffRatio | — |
SecurePagesProcessed | — |
HiberChecksumTime | — |
HiberChecksumIoTime | — |
ResumeChecksumTime | — |
ResumeChecksumIoTime | — |
KernelChecksumTime | — |
KernelChecksumIoTime | — |
WinresumeExitTimestamp | — |
TcbLoaderStartTimestamp | — |
TcbLoaderEndTimestamp | — |
RemappedPageLookupCycles | — |
TcbLaunchPrepareCycles | — |
TcbLaunchPrepareDataCycles | — |
DecryptVsmPagesPhase0Cycles | — |
DecryptVsmPagesPhase1Cycles | — |
DecryptVsmPagesPhase2Cycles | — |
TcbLoaderAuthenticateCycles | — |
TcbLoaderDecryptCycles | — |
TcbLoaderValidateCycles | — |
Event ID 118 — Idle resiliency activated with requested clock period: %1(Internal flags:%2, Ticks:%3).
Message
Fields
| Name | Description |
|---|---|
RequestedResolution | — |
Flags | — |
Ticks | — |
Event ID 119 — Idle resiliency deactivated (Internal flags:%2).
Message
Fields
| Name | Description |
|---|---|
RequestedResolution | — |
Flags | — |
Ticks | — |
Event ID 120 —
Fields
| Name | Description |
|---|---|
HiberfileSizeKB | — |
TotalHibernateTime | — |
HiberHiberFileTime | — |
Event ID 121 —
Fields
| Name | Description |
|---|---|
DriverWakeTime | — |
TotalResumeTime | — |
BiosInitTime | — |
ResumeAppsTime | — |
ResumeServicesTime | — |
Event ID 122 —
Fields
| Name | Description |
|---|---|
TotalResumeTime | — |
PhasePagesWrittenMB | — |
ResumeAppAndKernelResumeHiberFileTime | — |
POSTAndDeviceResumeTime | — |
RatesAndResumeAppsServicesTime | — |
PhasePagesProcessedMB | — |
Event ID 123 —
Fields
| Name | Description |
|---|---|
HiberfileSize | — |
TotalHybridShutdownTime | — |
HiberfileCreateTime | — |
SystemShutdownTime | — |
Event ID 124 —
Fields
| Name | Description |
|---|---|
TotalResumeTime | — |
PhasePagesWrittenMB | — |
ResumeAppAndKernelResumeHiberFileTime | — |
POSTAndDeviceResumeTime | — |
RatesAndResumeAppsServicesTime | — |
PhasePagesProcessedMB | — |
Event ID 125 — ACPI thermal zone %2 has been enumerated.
Message
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
_PSV | — |
_TC1 | — |
_TC2 | — |
_TSP | — |
_AC0 | — |
_AC1 | — |
_AC2 | — |
_AC3 | — |
_AC4 | — |
_AC5 | — |
_AC6 | — |
_AC7 | — |
_AC8 | — |
_AC9 | — |
_CRT | — |
_HOT | — |
MinimumThrottle | — |
_CR3 | — |
OverThrottleThreshold | — |
DescriptionLength | — |
Description | — |
_TZP | — |
Event ID 126 —
Fields
| Name | Description |
|---|---|
Level | — |
MinorFunction | — |
Event ID 127 —
Fields
| Name | Description |
|---|---|
Level | — |
MinorFunction | — |
Event ID 128 —
Fields
| Name | Description |
|---|---|
Level | — |
MinorFunction | — |
Event ID 129 —
Fields
| Name | Description |
|---|---|
Level | — |
MinorFunction | — |
Event ID 130 — Firmware S3 times.
Message
Fields
| Name | Description |
|---|---|
Firmware_S3_times_SuspendStart | Firmware S3 times. SuspendStart. |
SuspendEnd | — |
SuspendStart | — |
Event ID 131 — Firmware S3 times.
Message
Fields
| Name | Description |
|---|---|
Firmware_S3_times_ResumeCount | Firmware S3 times. ResumeCount. |
FullResume | — |
AverageResume | — |
ResumeCount | — |
Event ID 132 —
Fields
| Name | Description |
|---|---|
PlatformRole | — |
Event ID 133 —
Event ID 134 —
Event ID 135 —
Fields
| Name | Description |
|---|---|
DisplayState | — |
Event ID 136 —
Fields
| Name | Description |
|---|---|
DeviceNode | — |
PowerState | — |
InstancePathLength | — |
InstancePath | — |
FriendlyNameLength | — |
FriendlyName | — |
Event ID 137 — The system firmware has changed the processor's memory type range registers (MTRRs) across a sleep state transition (S%1).
Message
Fields
| Name | Description |
|---|---|
SleepState | — |
Event ID 138 —
Fields
| Name | Description |
|---|---|
Throttle | — |
Temperature | — |
ZoneLength | — |
Zone | — |
Event ID 139 —
Fields
| Name | Description |
|---|---|
ThrottleDuration | — |
ZoneLength | — |
Zone | — |
Event ID 140 —
Fields
| Name | Description |
|---|---|
EnergyDrain | — |
Duration | — |
DripsTransitions | — |
Flags | — |
Event ID 141 —
Fields
| Name | Description |
|---|---|
FanDuration | — |
ActivationDelay | — |
Event ID 142 — The system has rebooted without cleanly shutting down first.
Message
Fields
| Name | Description |
|---|---|
ResetReasonMask | — |
Event ID 143 —
Fields
| Name | Description |
|---|---|
ResiliencyPhaseNonActivatedNoDripsMs | — |
NonActivatedCpuTimeMs | — |
DurationThisPeriodMs | — |
ActionsTakenAndOnAc | — |
Event ID 144 —
Fields
| Name | Description |
|---|---|
InitiatorLength | — |
Initiator | — |
Type | — |
Temperature | — |
TripPointTemperature | — |
Event ID 145 —
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
ActiveCoolingState | — |
ActivePoint | — |
PassiveCoolingState | — |
ThrottleLimit | — |
ThermalStandby | — |
OverThrottled | — |
DescriptionLength | — |
Description | — |
Event ID 146 —
Fields
| Name | Description |
|---|---|
Callback | — |
SettingGuid | — |
DataSize | — |
Data | — |
Event ID 147 —
Fields
| Name | Description |
|---|---|
Callback | — |
SettingGuid | — |
Event ID 148 —
Fields
| Name | Description |
|---|---|
State | — |
Reason | — |
Event ID 149 —
Fields
| Name | Description |
|---|---|
Session | — |
Console | — |
Reason | — |
Event ID 150 —
Fields
| Name | Description |
|---|---|
Session | — |
Console | — |
Reason | — |
Event ID 151 —
Fields
| Name | Description |
|---|---|
PassiveSupported | — |
ActiveSupported | — |
Throttle | — |
ActiveEngaged | — |
Token | — |
DeviceIdLength | — |
DeviceId | — |
Event ID 152 —
Fields
| Name | Description |
|---|---|
PassiveSupported | — |
ActiveSupported | — |
Throttle | — |
ActiveEngaged | — |
Token | — |
DeviceIdLength | — |
DeviceId | — |
Event ID 153 —
Fields
| Name | Description |
|---|---|
PassiveSupported | — |
ActiveSupported | — |
Throttle | — |
ActiveEngaged | — |
Token | — |
DeviceIdLength | — |
DeviceId | — |
Event ID 154 —
Fields
| Name | Description |
|---|---|
Throttle | — |
Token | — |
Event ID 155 —
Fields
| Name | Description |
|---|---|
ActiveEngaged | — |
Token | — |
Event ID 156 —
Fields
| Name | Description |
|---|---|
Throttle | — |
ActiveEngaged | — |
Token | — |
DeviceIdLength | — |
CallerLength | — |
ContextLength | — |
PolicyLength | — |
DeviceId | — |
Caller | — |
Context | — |
Policy | — |
Event ID 157 —
Fields
| Name | Description |
|---|---|
Throttle | — |
ActiveEngaged | — |
Token | — |
DeviceIdLength | — |
CallerLength | — |
ContextLength | — |
PolicyLength | — |
DeviceId | — |
Caller | — |
Context | — |
Policy | — |
Event ID 158 —
Fields
| Name | Description |
|---|---|
Throttle | — |
ActiveEngaged | — |
Token | — |
DeviceIdLength | — |
CallerLength | — |
ContextLength | — |
PolicyLength | — |
DeviceId | — |
Caller | — |
Context | — |
Policy | — |
Event ID 159 —
Fields
| Name | Description |
|---|---|
Throttle | — |
Token | — |
Event ID 160 —
Fields
| Name | Description |
|---|---|
ActiveEngaged | — |
Token | — |
Event ID 161 —
Fields
| Name | Description |
|---|---|
ResiliencyPhaseNonActivatedNoDripsMs | — |
NonActivatedCpuTimeMs | — |
DurationThisPeriodMs | — |
OnAc | — |
EnergyDrainMw | — |
DeviceConstraint | — |
ActionsTaken | — |
DeviceServiceNameLength | — |
DeviceServiceName | — |
ChildServiceNameLength | — |
ChildServiceName | — |
PepPreVeto | — |
InvocationCount | — |
Event ID 162 —
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
Engaged | — |
Event ID 163 —
Fields
| Name | Description |
|---|---|
ThermalZoneDeviceInstanceLength | — |
ThermalZoneDeviceInstance | — |
Engaged | — |
Event ID 164 —
Event ID 165 —
Fields
| Name | Description |
|---|---|
IdleInformationUpdated | — |
TimeoutSource | — |
Action | — |
MinState | — |
Timeout | — |
Flags | — |
Reason | — |
Event ID 166 —
Fields
| Name | Description |
|---|---|
AccumulatedIdleTime | — |
SystemIdle | — |
Flags | — |
Action | — |
MinState | — |
DozeS4Timeout | — |
PredictedUserReturnTime | — |
Event ID 167 —
Fields
| Name | Description |
|---|---|
Reason | — |
S0LowPowerDozeTimerCancelled | — |
Event ID 168 —
Fields
| Name | Description |
|---|---|
CancelledDueToUserInput | — |
Event ID 169 —
Fields
| Name | Description |
|---|---|
Source | — |
Time | — |
Event ID 170 —
Fields
| Name | Description |
|---|---|
Reason | — |
Event ID 171 —
Fields
| Name | Description |
|---|---|
ResiliencyPhaseNonActivatedNoDeepSleepMs | — |
NonActivatedCpuTimeMs | — |
DurationThisPeriodMs | — |
OnAc | — |
ActionsTaken | — |
PowerSettingPending | — |
Event ID 172 — Connectivity state in standby: %1, Reason: %2.
Message
Fields
| Name | Description |
|---|---|
State | Connectivity state in standby. |
Reason | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-Power
guid: 331C3B3A-2005-44C2-AC5E-77220C37D6B4
event_source_name: ''
event_id: 172
version: 0
level: 4
task: 203
opcode: 0
keywords: 9223372036854776836
time_created: '2023-11-06T06:25:19.594800+00:00'
event_record_id: 1646
correlation: {}
execution:
process_id: 4
thread_id: 228
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
State: 2
Reason: 6
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 173 —
Event ID 174 —
Event ID 175 —
Fields
| Name | Description |
|---|---|
State | — |
Reason | — |
Event ID 176 —
Fields
| Name | Description |
|---|---|
Type | — |
State | — |
Event ID 177 —
Fields
| Name | Description |
|---|---|
Type | — |
State | — |
Event ID 178 — Background Activity Policy updated from %1 to %2.
Message
Fields
| Name | Description |
|---|---|
PreviousPolicy | — |
NewPolicy | — |
Event ID 179 —
Fields
| Name | Description |
|---|---|
PrevState | — |
NewState | — |
Event ID 180 —
Fields
| Name | Description |
|---|---|
Reason | — |
Event ID 181 —
Fields
| Name | Description |
|---|---|
Constraint | — |
Event ID 182 —
Fields
| Name | Description |
|---|---|
Constraint | — |
Event ID 183 —
Fields
| Name | Description |
|---|---|
ConstraintCount | — |
Constraints | — |
Event ID 184 —
Fields
| Name | Description |
|---|---|
ExpiryCount | — |
RelativeId | — |
ComponentName | — |
Event ID 185 —
Fields
| Name | Description |
|---|---|
WokeSystem | — |
RejectReason | — |
Uncertain | — |
Spurious | — |
FixedWakeSourceMask | — |
AcAlarmSignaled | — |
DcAlarmSignaled | — |
RtcSignaled | — |
AcProgrammedTime | — |
DcProgrammedTime | — |
UsingAcTime | — |
WakeTime | — |
AdjustedWakeTime | — |
FullWake | — |
Event ID 186 —
Fields
| Name | Description |
|---|---|
Irp | — |
Event ID 187 — User-mode process attempted to change the system state by calling SetSuspendState or SetSystemPowerState APIs.
Message
Fields
| Name | Description |
|---|---|
ApiCallerNameLength | — |
ApiCallerName | — |
SystemAction | — |
LightestSystemState | — |
Event ID 188 —
Event ID 189 —
Event ID 190 —
Fields
| Name | Description |
|---|---|
RequestIgnored | — |
Pid | — |
Event ID 191 —
Fields
| Name | Description |
|---|---|
Count | — |
Event ID 200 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmSid | — |
SqmWindowsSessionId | — |
SqmSessionFlags | — |
Event ID 201 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
Event ID 202 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmID | — |
SqmDWORDDatapointValue | — |
Event ID 203 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmID | — |
SqmDWORDDatapointValue | — |
Event ID 204 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmID | — |
SqmDWORDDatapointValue | — |
Event ID 205 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmID | — |
SqmDWORDDatapointValue | — |
Event ID 206 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmID | — |
SqmDWORDDatapointValue | — |
Event ID 207 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmID | — |
SqmStringDatapointValue | — |
Event ID 208 —
Fields
| Name | Description |
|---|---|
SqmType | — |
SqmSessionGuid | — |
SqmID | — |
SqmStreamRowLength | — |
SqmStreamRow | — |
Event ID 300 —
Fields
| Name | Description |
|---|---|
Plugin | — |
Attributes | — |
Event ID 301 —
Fields
| Name | Description |
|---|---|
Plugin | — |
Attributes | — |
Event ID 302 —
Fields
| Name | Description |
|---|---|
Token | — |
Plugin | — |
IdLength | — |
Id | — |
Prepared | — |
Event ID 303 —
Fields
| Name | Description |
|---|---|
Token | — |
Plugin | — |
PowerState | — |
Status | — |
IdLength | — |
Id | — |
ComponentCount | — |
VetoMasks | — |
Event ID 304 —
Fields
| Name | Description |
|---|---|
Token | — |
Plugin | — |
PowerState | — |
Status | — |
IdLength | — |
Id | — |
ComponentCount | — |
VetoMasks | — |
Event ID 305 —
Fields
| Name | Description |
|---|---|
Token | — |
Event ID 306 —
Fields
| Name | Description |
|---|---|
Token | — |
Event ID 307 —
Fields
| Name | Description |
|---|---|
Token | — |
PowerRequired | — |
Event ID 308 —
Fields
| Name | Description |
|---|---|
Token | — |
PowerState | — |
Event ID 309 —
Fields
| Name | Description |
|---|---|
Token | — |
Event ID 310 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Active | — |
IdleState | — |
IdleStateCount | — |
IdleStates | — |
Event ID 311 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Active | — |
IdleState | — |
IdleStateCount | — |
IdleStates | — |
Event ID 312 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Active | — |
Event ID 313 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
IdleState | — |
Event ID 314 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Latency | — |
Event ID 315 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Residency | — |
Event ID 316 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
ArmedForWake | — |
Event ID 317 —
Fields
| Name | Description |
|---|---|
Token | — |
PowerRequired | — |
Event ID 318 —
Fields
| Name | Description |
|---|---|
Token | — |
StateCount | — |
MinimumDStates | — |
Event ID 319 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
StateCount | — |
MinimumFStates | — |
Event ID 320 —
Fields
| Name | Description |
|---|---|
DeviceNode | — |
DeviceIdLength | — |
DeviceId | — |
InstancePathLength | — |
InstancePath | — |
ServiceNameLength | — |
ServiceName | — |
PlatformStateDependents | — |
Pdo | — |
ParentDeviceNode | — |
Flags | — |
FriendlyNameLength | — |
FriendlyName | — |
DripsRequiredState | — |
Event ID 321 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
SetCount | — |
Event ID 322 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
SetCount | — |
Event ID 323 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Set | — |
NameLength | — |
Name | — |
Type | — |
Unit | — |
Minimum | — |
Maximum | — |
StateCount | — |
StateValues | — |
CurrentState | — |
Event ID 324 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Set | — |
NameLength | — |
Name | — |
Type | — |
Unit | — |
Minimum | — |
Maximum | — |
StateCount | — |
StateValues | — |
CurrentState | — |
Event ID 325 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
PerformanceStateSetCount | — |
PerformanceStateSets | — |
Event ID 326 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Progress | — |
Event ID 327 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
Succeeded | — |
Event ID 328 —
Fields
| Name | Description |
|---|---|
Token | — |
Component | — |
DeviceTransition | — |
PowerState | — |
PerformanceStateSetCount | — |
PerformanceStateSets | — |
Event ID 329 —
Fields
| Name | Description |
|---|---|
Token | — |
StateCount | — |
TransitionRequired | — |
Event ID 330 —
Fields
| Name | Description |
|---|---|
StartDevice | — |
Event ID 331 —
Fields
| Name | Description |
|---|---|
EndDevice | — |
WorkType | — |
Phase | — |
NumberExtraDevices | — |
Event ID 332 —
Fields
| Name | Description |
|---|---|
EndDevice | — |
WorkType | — |
Phase | — |
NumberExtraDevices | — |
Event ID 333 —
Fields
| Name | Description |
|---|---|
EndDevice | — |
WorkType | — |
Phase | — |
NumberExtraDevices | — |
Event ID 400 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 401 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 402 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 403 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 404 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 405 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 406 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 407 — SessionId: %1, Console:%2.
Message
Fields
| Name | Description |
|---|---|
SessionId | — |
Console | — |
Event ID 408 — User presence.
Message
Fields
| Name | Description |
|---|---|
User_presence | — |
UserPresence | — |
Event ID 409 — Reason code.
Message
Fields
| Name | Description |
|---|---|
Reason_code | — |
Code | — |
Event ID 410 — Engaged.
Message
Fields
| Name | Description |
|---|---|
Engaged | — |
Event ID 411 — Engaged.
Message
Fields
| Name | Description |
|---|---|
Engaged | — |
Event ID 412 — Session Id:%1, Value: %2.
Message
Fields
| Name | Description |
|---|---|
Session_Id | — |
Value | — |
SessionId | — |
State | — |
Event ID 413 — Session Id:%1, Value: %2.
Message
Fields
| Name | Description |
|---|---|
Session_Id | — |
Value | — |
SessionId | — |
State | — |
Event ID 414 — Session Id:%1, Value: %2.
Message
Fields
| Name | Description |
|---|---|
Session_Id | — |
Value | — |
SessionId | — |
State | — |
TransitionCount | — |
Event ID 415 — Old value:%1, New value: %2.
Message
Fields
| Name | Description |
|---|---|
Old_value | — |
New_value | — |
Old | — |
New | — |
Event ID 416 — Value:%1, Zeroed: %2, Computed: %3.
Message
Fields
| Name | Description |
|---|---|
Value | — |
Zeroed | — |
Computed | — |
Event ID 417 — Value:%1, Zeroed: %2, Computed: %3.
Message
Fields
| Name | Description |
|---|---|
Value | — |
Zeroed | — |
Computed | — |
Event ID 418 — Value:%1, Zeroed: %2, Computed: %3.
Message
Fields
| Name | Description |
|---|---|
Value | — |
Zeroed | — |
Computed | — |
SensorDisplayTimeout | — |
DisplayTimeout | — |
SensorInputTimeout | — |
InputTimeout | — |
SessionLockedTimeout | — |
SensorEnabled | — |
Event ID 500 — IO coalescing activated with spindown period: %1, Timer:%2, Flush:%3, Flags:%4.
Message
Fields
| Name | Description |
|---|---|
SpindownTimeout | — |
TimerInterval | — |
FlushInterval | — |
Flags | — |
Event ID 501 — IO coalescing deactivated.
Message
Event ID 502 — IO coalescing flush command generated.
Message
Event ID 503 — IO coalescing disk device %1 is about to be spun down.
Message
Fields
| Name | Description |
|---|---|
DiskDeviceObject | — |
Event ID 504 —
Fields
| Name | Description |
|---|---|
SystemLatency | — |
Event ID 505 —
Fields
| Name | Description |
|---|---|
SystemLatency | — |
Event ID 506 — The system is entering Modern Standby Reason.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
LidOpenState | — |
ExternalMonitorConnectedState | — |
ScenarioInstanceId | — |
BatteryRemainingCapacityOnEnter | — |
BatteryFullChargeCapacityOnEnter | — |
ScenarioInstanceIdV2 | — |
BootId | — |
Event ID 507 — The system is exiting Modern Standby Reason.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
EnergyDrain | — |
ActiveResidencyInUs | — |
NonDripsTimeActivatedInUs | — |
FirstDripsEntryInUs | — |
DripsResidencyInUs | — |
DurationInUs | — |
DripsTransitions | — |
FullChargeCapacityRatio | — |
AudioPlaying | — |
AudioPlaybackInUs | — |
NonActivatedCpuInUs | — |
PowerStateAc | — |
HwDripsResidencyInUs | — |
ExitLatencyInUs | — |
DisconnectedStandby | — |
AoAcCompliantNic | — |
NonAttributedCpuInUs | — |
ModernSleepEnabledActionsBitmask | — |
ModernSleepAppliedActionsBitmask | — |
LidOpenState | — |
ExternalMonitorConnectedState | — |
ScenarioInstanceId | — |
IsCsSessionInProgressOnExit | — |
BatteryRemainingCapacityOnExit | — |
BatteryFullChargeCapacityOnExit | — |
ScenarioInstanceIdV2 | — |
BootId | — |
InputSuppressionActionCount | — |
NonResiliencyTimeInUs | — |
ResiliencyDripsTimeInUs | — |
ResiliencyHwDripsTimeInUs | — |
GdiOnTime | — |
DwmSyncFlushTime | — |
MonitorPowerOnTime | — |
SleepEntered | — |
ScreenOffEnergyCapacityAtStart | — |
ScreenOffEnergyCapacityAtEnd | — |
ScreenOffDurationInUs | — |
SleepEnergyCapacityAtStart | — |
SleepEnergyCapacityAtEnd | — |
SleepDurationInUs | — |
ScreenOffFullEnergyCapacityAtStart | — |
ScreenOffFullEnergyCapacityAtEnd | — |
SleepFullEnergyCapacityAtStart | — |
SleepFullEnergyCapacityAtEnd | — |
PowerSchemeInfo | — |
PowerButtonSuppressionActionCount | — |
ScreenOffSwDripsResidencyInUs | — |
ScreenOffHwDripsResidencyInUs | — |
SleepSwDripsResidencyInUs | — |
SleepHwDripsResidencyInUs | — |
Event ID 508 — The system has been constrained to a periodic tick Reason.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Event ID 509 —
Fields
| Name | Description |
|---|---|
Flags | — |
Event ID 510 — Scenario Power Manager (SPM) policy framework has current status.
Message
Fields
| Name | Description |
|---|---|
SpmStatus | — |
Event ID 511 —
Fields
| Name | Description |
|---|---|
SpmStatus | — |
Event ID 512 —
Fields
| Name | Description |
|---|---|
PolicyGuid | — |
PolicyAliasLength | — |
PolicyAlias | — |
Event ID 513 —
Fields
| Name | Description |
|---|---|
ScenarioGuid | — |
ScenarioNameLength | — |
ScenarioName | — |
Flags | — |
DefaultSettingsScenarioGuid | — |
PolicyCount | — |
PolicySettings | — |
Event ID 518 —
Event ID 519 —
Event ID 520 — The brightness on this system is managed by high-precision brightness aware service.
Message
Event ID 521 — Active battery count change.
Message
Fields
| Name | Description |
|---|---|
ValidBatteryCount | — |
ErrorBatteryCount | — |
AbandonedBatteryCount | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-Power
guid: 331C3B3A-2005-44C2-AC5E-77220C37D6B4
event_source_name: ''
event_id: 521
version: 0
level: 4
task: 220
opcode: 0
keywords: 9223372036854776836
time_created: '2022-04-04T13:11:11.019552+00:00'
event_record_id: 1541
correlation: {}
execution:
process_id: 4
thread_id: 260
channel: System
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-18
event_data:
ValidBatteryCount: 1
ErrorBatteryCount: 0
AbandonedBatteryCount: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 522 —
Fields
| Name | Description |
|---|---|
HwDripsTotalTimeValid | — |
DripsTotalTimeThisPeriodUs | — |
HwDripsTotalTimeThisPeriodUs | — |
PopDripsSwHwDivergenceThreshold | — |
Event ID 523 —
Fields
| Name | Description |
|---|---|
Irp | — |
Status | — |
FailedDriver | — |
ElapsedTime | — |
Event ID 524 — %1 Battery Trigger Met.
Message
Fields
| Name | Description |
|---|---|
Index | — |
ActiveBatteryCount | — |
RemainingPercentage | — |
IsAcOnline | — |
BatteryActionInternalFlags | — |
IsPowerActionCallIgnored | — |
IsPowerPolicyEnabled | — |
PowerPolicyAction | — |
PowerPolicyBatteryLevel | — |
PowerPolicyEventCode | — |
PowerPolicyMinState | — |
Event ID 525 —
Fields
| Name | Description |
|---|---|
DurationInUs | — |
Event ID 526 —
Event ID 527 —
Fields
| Name | Description |
|---|---|
Event | — |
Class | — |
Count | — |
Event ID 528 —
Fields
| Name | Description |
|---|---|
Event | — |
Intent | — |
Event ID 529 —
Fields
| Name | Description |
|---|---|
Intent | — |
Class | — |
PowerEvent | — |
Event ID 530 —
Fields
| Name | Description |
|---|---|
SessionId | — |
RequestQueueId | — |
Intent | — |
Class | — |
PowerEvent | — |
VetoReason | — |
Event ID 531 —
Fields
| Name | Description |
|---|---|
SessionId | — |
Action | — |
Result | — |
Event ID 532 —
Fields
| Name | Description |
|---|---|
SessionId | — |
Result | — |
Event ID 533 —
Fields
| Name | Description |
|---|---|
SessionId | — |
PowerEvent | — |
Action | — |
AudioActivity | — |
DisconnectedStandbyMode | — |
DsEnabled | — |
Event ID 534 —
Fields
| Name | Description |
|---|---|
SessionId | — |
Result | — |
Event ID 535 —
Fields
| Name | Description |
|---|---|
CsSessionId | — |
Engaged | — |
CsSessionIdV2 | — |
Event ID 536 —
Fields
| Name | Description |
|---|---|
CsSessionId | — |
WorkFlags | — |
CsSessionIdV2 | — |
Event ID 537 —
Fields
| Name | Description |
|---|---|
CsSessionId | — |
DeviceObject | — |
Event ID 538 —
Fields
| Name | Description |
|---|---|
CsSessionId | — |
Suspended | — |
Result | — |
DurationMs | — |
CsSessionIdV2 | — |
Event ID 539 —
Fields
| Name | Description |
|---|---|
CsSessionId | — |
Suspended | — |
Result | — |
DurationMs | — |
CsSessionIdV2 | — |
Event ID 540 —
Fields
| Name | Description |
|---|---|
EnableResult | — |
InitializationResult | — |
Event ID 541 —
Fields
| Name | Description |
|---|---|
SystemIdle | — |
Status | — |
TimeoutSource | — |
Event ID 542 —
Fields
| Name | Description |
|---|---|
RequestIndex | — |
NumberOfRequests | — |
QueueSize | — |
Event ID 544 —
Fields
| Name | Description |
|---|---|
OldMask | — |
NewMask | — |
SetFlags | — |
ClearedFlags | — |
Event ID 545 —
Fields
| Name | Description |
|---|---|
BroadcastTreeId | — |
IsRootDevice | — |
DeviceNode | — |
InstancePathLength | — |
InstancePath | — |
VisitType | — |
Event ID 546 —
Fields
| Name | Description |
|---|---|
BroadcastTreeId | — |
DeviceNode | — |
Reason | — |
Event ID 547 —
Fields
| Name | Description |
|---|---|
DeviceNode | — |
PowerDown | — |
Event ID 548 —
Fields
| Name | Description |
|---|---|
DeviceNode | — |
PowerDown | — |
DevicePowerState | — |
Event ID 549 —
Fields
| Name | Description |
|---|---|
IdleTimeout | — |
NotIdleEvents | — |
IsSystemIdle | — |
Event ID 550 —
Fields
| Name | Description |
|---|---|
EventType | — |
TimeSinceEvent | — |
IdleTimeout | — |
WasIgnored | — |
BusyReason | — |
Event ID 551 —
Fields
| Name | Description |
|---|---|
ScanInterval | — |
Event ID 552 —
Fields
| Name | Description |
|---|---|
Reason | — |
PreviousTimeoutSource | — |
PreviousTimeout | — |
NewTimeoutSource | — |
NewTimeout | — |
Event ID 553 —
Fields
| Name | Description |
|---|---|
FxDevice | — |
DeviceNode | — |
InstancePathLength | — |
InstancePath | — |
Event ID 554 —
Fields
| Name | Description |
|---|---|
CsSessionId | — |
DeviceNode | — |
FriendlyNameLength | — |
FriendlyName | — |
HardwareIdLength | — |
HardwareId | — |
DeviceClassNameLength | — |
DeviceClassName | — |
DeviceClassGuidLength | — |
DeviceClassGuid | — |
BroadcastTreeId | — |
DfxTransitionCount | — |
Ps4TransitionCount | — |
Flags | — |
Event ID 555 —
Fields
| Name | Description |
|---|---|
Reason | — |
TriggerFlags | — |
UserNotify | — |
PowerAction | — |
PowerActionFlags | — |
PowerActionEventCode | — |
MinState | — |
SubstitutionPolicy | — |
LocalPowerAction | — |
LocalPowerActionFlags | — |
LocalPowerActionEventCode | — |
Disabled | — |
RequesterNameLength | — |
RequesterName | — |
Event ID 556 —
Fields
| Name | Description |
|---|---|
SessionId | — |
RootDeviceNode | — |
ErrorDeviceNode | — |
ReasonCode | — |
Count | — |
Event ID 557 — A driver is attempting to update the system timer resolution to a value of %1.
Message
Fields
| Name | Description |
|---|---|
RequestedResolution | — |
Tag | — |
Event ID 558 —
Fields
| Name | Description |
|---|---|
Intent | — |
Class | — |
Cause | — |
Status | — |
CurrentTargetState | — |
NextTargetState | — |
PartA_PrivTags | — |
TriageContextLength | — |
TriageContext | — |
Event ID 559 —
Event ID 560 —
Event ID 561 —
Fields
| Name | Description |
|---|---|
CurrentInternalState | — |
NextInternalState | — |
Event ID 562 —
Fields
| Name | Description |
|---|---|
CurrentTargetState | — |
CurrentInternalState | — |
Event ID 563 —
Event ID 564 —
Fields
| Name | Description |
|---|---|
IsSleepEnter | — |
Token | — |
CurrentTargetState | — |
CurrentInternalState | — |
Status | — |
Event ID 565 —
Fields
| Name | Description |
|---|---|
Suspended | — |
SuspendCount | — |
Event ID 566 — The system session has transitioned from %3 to %10.
Message
Fields
| Name | Description |
|---|---|
BootId | — |
Reason | — |
PreviousSessionId | — |
PreviousSessionType | — |
PreviousSessionDurationInUs | — |
PreviousEnergyCapacityAtStart | — |
PreviousFullEnergyCapacityAtStart | — |
PreviousEnergyCapacityAtEnd | — |
PreviousFullEnergyCapacityAtEnd | — |
NextSessionId | — |
NextSessionType | — |
PowerStateAc | — |
MonitorReason | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-Power
guid: 331C3B3A-2005-44C2-AC5E-77220C37D6B4
event_source_name: ''
event_id: 566
version: 0
level: 4
task: 268
opcode: 0
keywords: 9223372036854777348
time_created: '2023-11-06T01:08:04.643524+00:00'
event_record_id: 2153
correlation: {}
execution:
process_id: 4
thread_id: 9012
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
BootId: 13
Reason: 32
PreviousSessionId: 1
PreviousSessionType: 1
PreviousSessionDurationInUs: 324168323
PreviousEnergyCapacityAtStart: 0
PreviousFullEnergyCapacityAtStart: 0
PreviousEnergyCapacityAtEnd: 0
PreviousFullEnergyCapacityAtEnd: 0
NextSessionId: 3
NextSessionType: 0
PowerStateAc: true
MonitorReason: 32
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 567 —
Event ID 568 —
Event ID 569 —
Event ID 570 —
Event ID 571 —
Event ID 572 —
Event ID 573 —
Event ID 574 —
Event ID 575 —
Fields
| Name | Description |
|---|---|
Token | — |
ReasonDescriptionLength | — |
ReasonDescription | — |
Event ID 576 —
Fields
| Name | Description |
|---|---|
SessionId | — |
LastInputTimestamp | — |
LastDisplayOffTimestamp | — |
SessionDisplayState | — |
DisplayTimeout | — |
InputTimeout | — |
NotifyOnNextUserInput | — |
DisplayTimeoutSource | — |
DimTimeout | — |
DimTimeoutSource | — |
Event ID 577 — The system has prepared for a system initiated reboot from %1.
Message
Fields
| Name | Description |
|---|---|
AdaptiveTargetState | — |
IsUnattended | — |
Status | — |
Example Event
system:
provider: Microsoft-Windows-Kernel-Power
guid: 331C3B3A-2005-44C2-AC5E-77220C37D6B4
event_source_name: ''
event_id: 577
version: 0
level: 4
task: 280
opcode: 0
keywords: 9223372036854775812
time_created: '2023-11-06T06:23:40.830310+00:00'
event_record_id: 1622
correlation: {}
execution:
process_id: 4
thread_id: 388
channel: System
computer: WinDev2310Eval
security:
user_id: ''
event_data:
AdaptiveTargetState: 0
IsUnattended: false
Status: 279
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 578 — The system has detected a system initiated reboot from %1.
Message
Fields
| Name | Description |
|---|---|
AdaptiveTargetState | — |
IsUnattended | — |
Event ID 579 —
Fields
| Name | Description |
|---|---|
ThreadToken | — |
Status | — |
FailurePoint | — |
Event ID 580 —
Fields
| Name | Description |
|---|---|
Result | — |
VirtualConsole | — |
SessionId | — |
MonitorOnReason | — |
Event ID 581 —
Fields
| Name | Description |
|---|---|
ParamToken | — |
AttachMode | — |
IsSingleSession | — |
SessionId | — |
Type | — |
IsSync | — |
Event ID 582 —
Fields
| Name | Description |
|---|---|
ParamToken | — |
PsStatus | — |
SkipReason | — |
Event ID 583 —
Fields
| Name | Description |
|---|---|
ParamToken | — |
AttachMode | — |
IsSingleSession | — |
SessionId | — |
EventNumber | — |
EventCode | — |
Event ID 584 —
Fields
| Name | Description |
|---|---|
ParamToken | — |
PsStatus | — |
SkipReason | — |
Event ID 585 —
Fields
| Name | Description |
|---|---|
ParameterToken | — |
AttachMode | — |
IsSingleSession | — |
SessionId | — |
PowerAction | — |
MinState | — |
PowerActionFlags | — |
PowerStateTask | — |
Event ID 586 —
Fields
| Name | Description |
|---|---|
ParamToken | — |
PsStatus | — |
SkipReason | — |
Event ID 587 —
Fields
| Name | Description |
|---|---|
Irp | — |
DeviceInstancePathLength | — |
DeviceInstancePath | — |
Event ID 588 —
Fields
| Name | Description |
|---|---|
TimerType | — |
Duration | — |
Event ID 589 —
Fields
| Name | Description |
|---|---|
TimerType | — |
Event ID 590 —
Fields
| Name | Description |
|---|---|
TimerType | — |
Event ID 591 —
Fields
| Name | Description |
|---|---|
Token | — |
DeviceIdLength | — |
DeviceId | — |
CallerLength | — |
Caller | — |
ContextLength | — |
Context | — |
ReasonLength | — |
Reason | — |
LimitCount | — |
Values | — |
Event ID 592 —
Fields
| Name | Description |
|---|---|
Token | — |
DeviceIdLength | — |
DeviceId | — |
CallerLength | — |
Caller | — |
ContextLength | — |
Context | — |
ReasonLength | — |
Reason | — |
LimitCount | — |
Values | — |
Event ID 593 —
Fields
| Name | Description |
|---|---|
Token | — |
DeviceIdLength | — |
DeviceId | — |
CallerLength | — |
Caller | — |
ContextLength | — |
Context | — |
ReasonLength | — |
Reason | — |
LimitCount | — |
Values | — |
Event ID 594 —
Fields
| Name | Description |
|---|---|
Token | — |
ReasonLength | — |
Reason | — |
LimitCount | — |
Values | — |
Event ID 595 —
Fields
| Name | Description |
|---|---|
Token | — |
DeviceIdLength | — |
DeviceId | — |
LimitCount | — |
Attributes | — |
Event ID 596 —
Fields
| Name | Description |
|---|---|
Token | — |
DeviceIdLength | — |
DeviceId | — |
LimitCount | — |
Attributes | — |
Event ID 597 —
Fields
| Name | Description |
|---|---|
Token | — |
DeviceIdLength | — |
DeviceId | — |
LimitCount | — |
Attributes | — |
Event ID 598 —
Fields
| Name | Description |
|---|---|
Token | — |
LimitCount | — |
Values | — |
Event ID 599 —
Fields
| Name | Description |
|---|---|
State | — |
Reason | — |
Event ID 600 —
Fields
| Name | Description |
|---|---|
Status | — |
FailurePoint | — |
Event ID 601 —
Fields
| Name | Description |
|---|---|
MinSVN | — |
HiberrsmSVN | — |
HiberrsmOSVersion | — |
Event ID 601 — Hibernate was disabled because invalid system binaries were detected.
Message
Fields
| Name | Description |
|---|---|
MinSVN | — |
HiberrsmSVN | — |
HiberrsmOSVersion | — |
Event ID 602 —
Fields
| Name | Description |
|---|---|
PrevState | — |
TargetState | — |
Promoted | — |
Entered | — |
SettingGuid | — |
NewSettingValue | — |