Microsoft-Windows-NDIS-PacketCapture
20 events across 1 channel
Event ID 1001 — Packet Fragment (%3 bytes), MiniportIfIndex %1, LowerIfIndex %2.
Message
Fields
| Name | Description |
|---|---|
MiniportIfIndex | — |
LowerIfIndex | — |
FragmentSize | — |
Fragment | — |
GftFlowEntryId | — |
GftOffloadInformation | — |
Event ID 1002 — Packet Metadata (%3 bytes).
Message
Fields
| Name | Description |
|---|---|
MiniportIfIndex | — |
LowerIfIndex | — |
MetadataSize | — |
Metadata | — |
Event ID 1003 — VMSwitch Packet Fragment (%9 bytes), MiniportIfIndex %1, LowerIfIndex %2.
Message
Fields
| Name | Description |
|---|---|
MiniportIfIndex | — |
LowerIfIndex | — |
SourcePortId | — |
SourcePortName | — |
SourceNicName | — |
SourceNicType | — |
DestinationCount | — |
FragmentSize | — |
Fragment | — |
OOBDataSize | — |
OOBData | — |
Destination | — |
Event ID 1011 — Capture Rules Count=.
Message
Fields
| Name | Description |
|---|---|
RulesCount | — |
Event ID 1012 — Driver Loaded (FriendlyName=%1 UniqueName=%2 ServiceName=%3).
Message
Fields
| Name | Description |
|---|---|
FriendlyName | — |
UniqueName | — |
ServiceName | — |
Version | — |
Event ID 1013 — Driver Unloaded (FriendlyName=%1 UniqueName=%2 ServiceName=%3).
Message
Fields
| Name | Description |
|---|---|
FriendlyName | — |
UniqueName | — |
ServiceName | — |
Version | — |
Event ID 1014 — Attached to miniport interface %1 above layer interface %2 with media type %3 (context=%4).
Message
Fields
| Name | Description |
|---|---|
MiniportIfIndex | — |
LowerIfIndex | — |
MediaType | — |
ReferenceContext | — |
Event ID 1015 — Detached from miniport interface %1 above layer interface %2 with media type %3 (context=%4).
Message
Fields
| Name | Description |
|---|---|
MiniportIfIndex | — |
LowerIfIndex | — |
MediaType | — |
ReferenceContext | — |
Event ID 1016 — Capture Rule: Id=.
Message
Fields
| Name | Description |
|---|---|
RuleId | — |
Directive | — |
Length | — |
Value | — |
Event ID 2001 — Driver load failed with status=.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 2002 — FilterAttach failed with status=.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 2003 — Received Invalid Capture Rule: Id=.
Message
Fields
| Name | Description |
|---|---|
RuleId | — |
Directive | — |
Length | — |
Value | — |
Event ID 3001 — Entering state '.
Message
Fields
| Name | Description |
|---|---|
PreviousState | — |
NextState | — |
Location | — |
Context | — |
Event ID 3002 — Entering state '.
Message
Fields
| Name | Description |
|---|---|
PreviousState | — |
NextState | — |
Location | — |
Context | — |
Event ID 5000 — Rx Packet Processing Start
Message
Event ID 5001 — Rx Packet Processing Complete
Message
Event ID 5002 — Tx Packet Processing Start
Message
Event ID 5003 — Tx Packet Processing Complete
Message
Event ID 5100 — Rundown: %1: %2 - %3, %4, %5.
Message
Fields
| Name | Description |
|---|---|
Rundown | — |
SourceId | — |
RundownId | — |
Param1 | — |
Param2 | — |
ParamStr | — |
Description | — |
Event ID 5101 — Event source: %1: %2, IfIndex: %3, LayerCount: %4.
Message
Fields
| Name | Description |
|---|---|
Event_source | — |
LayerCount | 2, IfIndex. |
SourceId | — |
SourceName | — |
IfIndex | — |
LayerInfo | — |