Microsoft-Windows-NDIS-PacketCapture
20 events across 1 channel
Event ID 1001 — Packet Fragment (FragmentSize bytes), MiniportIfIndex MiniportIfIndex, LowerIfIndex LowerIfIndex.
Event ID 1002 — Packet Metadata (MetadataSize bytes).
Event ID 1003 — VMSwitch Packet Fragment (Fragment bytes), MiniportIfIndex MiniportIfIndex, LowerIfIndex LowerIfIndex.
Description
VMSwitch Packet Fragment (Fragment bytes), MiniportIfIndex MiniportIfIndex, LowerIfIndex LowerIfIndex.
Message #
Fields #
| Name | Description |
|---|---|
MiniportIfIndex UInt32 | — |
LowerIfIndex UInt32 | — |
SourcePortId UInt32 | — |
SourcePortName UnicodeString | — |
SourceNicName UnicodeString | — |
SourceNicType UnicodeString | — |
DestinationCount UInt32 | — |
FragmentSize UInt32 | — |
Fragment Binary | — |
OOBDataSize UInt32 | — |
OOBData Binary | — |
Destination Double | — |
Event ID 1011 — Capture Rules Count=RulesCount.
Event ID 1012 — Driver Loaded (FriendlyName=FriendlyName UniqueName=UniqueName ServiceName=ServiceName).
Event ID 1013 — Driver Unloaded (FriendlyName=FriendlyName UniqueName=UniqueName ServiceName=ServiceName).
Event ID 1014 — Attached to miniport interface MiniportIfIndex above layer interface LowerIfIndex with media type MediaType (context=ReferenceContext).
Event ID 1015 — Detached from miniport interface MiniportIfIndex above layer interface LowerIfIndex with media type MediaType (context=ReferenceContext).
Event ID 1016 — Capture Rule: Id=RuleId Directive=Directive ValueLength=Length Value=Value.
Event ID 2001 — Driver load failed with status=ErrorCode at location Location.
Event ID 2002 — FilterAttach failed with status=ErrorCode at location Location (context=Context).
Event ID 2003 — Received Invalid Capture Rule: Id=RuleId Directive=Directive ValueLength=Length Value=Value.
Event ID 3001 — Entering state 'NextState' from state 'PreviousState' (location=Location, context=Context).
Event ID 3002 — Entering state 'NextState' from state 'PreviousState' (location=Location, context=Context).
Event ID 5000 — Rx Packet Processing Start
Description
Rx Packet Processing Start.
Message #
Event ID 5001 — Rx Packet Processing Complete
Description
Rx Packet Processing Complete.
Message #
Event ID 5002 — Tx Packet Processing Start
Description
Tx Packet Processing Start.
Message #
Event ID 5003 — Tx Packet Processing Complete
Description
Tx Packet Processing Complete.