Microsoft-Windows-Ntfs
72 events across 4 channels
Event ID 1 — RundownStart
Message
Event ID 2 — RundownComplete
Message
Event ID 3 — RundownVolumeInformation VolumeId: %1, DeviceName: %3.
Message
Fields
| Name | Description |
|---|---|
RundownVolumeInformation_VolumeId | — |
DeviceName | — |
Vcb | — |
DeviceNameLength | — |
Event ID 4 — The NTFS volume has been successfully mounted.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | Volume name. |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | Device manufacturer. |
ProductIdLength | — |
ProductId | Device model. |
ProductRevisionLength | — |
ProductRevision | Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Vcb | — |
MountDurationUs | — |
MountDuration | Total mount duration. |
LongestStage | — |
LongestStageDuration | — |
LongestStagePercentage | — |
SecondLongestStage | — |
SecondLongestStageDuration | — |
SecondLongestStagePercentage | — |
RestartApplied | Volume restart applied. |
IsBootVolume | — |
Stage1DurationUs | — |
Stage2DurationUs | — |
Stage3DurationUs | — |
Stage4DurationUs | — |
Stage5DurationUs | — |
Stage6DurationUs | — |
Stage7DurationUs | — |
Stage8DurationUs | — |
Stage9DurationUs | — |
Stage10DurationUs | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 4
version: 1
level: 4
task: 6
opcode: 0
keywords: 4611967493404098592
time_created: '2023-11-06T06:25:20.848685+00:00'
event_record_id: 147
correlation: {}
execution:
process_id: 4
thread_id: 96
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: F8B2740A-2324-44DB-BBF8-80523FE5334B
VolumeIdLength: 48
VolumeId: \\?\Volume{f8b2740a-2324-44db-bbf8-80523fe5334b}
VolumeLabelLength: 5
VolumeLabel: WINRE
DeviceNameLength: 23
DeviceName: \Device\HarddiskVolume1
DeviceGuid: 33A0A150-7C6D-11EE-9369-806E6F6E6963
VendorIdLength: 8
VendorId: 'VMware, '
ProductIdLength: 16
ProductId: VMware Virtual S
ProductRevisionLength: 4
ProductRevision: '1.0 '
DeviceSerialNumberLength: 0
DeviceSerialNumber: ''
BusType: 10
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
Vcb: '0xffffa60dd18c01b0'
MountDurationUs: 32215
MountDuration: 32 ms
LongestStage: 5
LongestStageDuration: 16 ms
LongestStagePercentage: 50
SecondLongestStage: 2
SecondLongestStageDuration: 16 ms
SecondLongestStagePercentage: 50
RestartApplied: false
IsBootVolume: false
Stage1DurationUs: 0
Stage2DurationUs: 16042
Stage3DurationUs: 0
Stage4DurationUs: 0
Stage5DurationUs: 16172
Stage6DurationUs: 0
Stage7DurationUs: 0
Stage8DurationUs: 0
Stage9DurationUs: 0
Stage10DurationUs: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5 — NTFS KSR data retrieved successfully.
Message
Fields
| Name | Description |
|---|---|
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
Version | — |
CachedRunsRestoredRunCount | — |
CachedRunsRestoredTimeMs | — |
Event ID 6 — NTFS KSR data retrieval failed.
Message
Fields
| Name | Description |
|---|---|
Device_Name | — |
Volume_GUID | — |
Error | Device Name. |
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
MessageLength | — |
Message | — |
FailureStatus | — |
SourceTag | — |
Event ID 7 — Ntfs has detected torn write on a volume.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
VolumeLabelLength | — |
VolumeLabel | — |
FileReference | — |
FileNameLength | — |
FileName | — |
BufferOffset | — |
TornStructureOffset | — |
BlockIndex | — |
ExpectedSequenceNumber | — |
ActualSequenceNumber | — |
FrsFileReference | — |
FrsFileNameLength | — |
FrsFileName | — |
IsChildFRS | — |
Event ID 8 — File's duplicate info has been updated during flush.
Message
Fields
| Name | Description |
|---|---|
Volume_correlation_Id | — |
Volume_name | — |
File_Reference | — |
File_Name | — |
File_Link_name | — |
Parent_file_reference | File Name. |
Parent_file_name | — |
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
FileReference | — |
FileNameLength | — |
FileName | — |
FileLinkNameLength | — |
FileLinkName | — |
ParentFileReference | — |
ParentFileNameLength | — |
ParentFileName | — |
Reason | — |
ReasonText | — |
Event ID 9 — NTFS scanned entire volume bitmap.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | Volume name. |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | Device manufacturer. |
ProductIdLength | — |
ProductId | Device model. |
ProductRevisionLength | — |
ProductRevision | Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
DurationUs | Duration (micro seconds). |
InputFlags | — |
Reason | — |
Flags | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 9
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018429485056
time_created: '2023-11-06T06:25:25.774221+00:00'
event_record_id: 149
correlation:
ActivityID: 405E6FE6-7C77-466B-8D93-5F354CA37E8C
execution:
process_id: 4
thread_id: 108
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: F8B2740A-2324-44DB-BBF8-80523FE5334B
VolumeIdLength: 48
VolumeId: \\?\Volume{f8b2740a-2324-44db-bbf8-80523fe5334b}
VolumeLabelLength: 5
VolumeLabel: WINRE
DeviceNameLength: 23
DeviceName: \Device\HarddiskVolume1
DeviceGuid: 33A0A150-7C6D-11EE-9369-806E6F6E6963
VendorIdLength: 8
VendorId: 'VMware, '
ProductIdLength: 16
ProductId: VMware Virtual S
ProductRevisionLength: 4
ProductRevision: '1.0 '
DeviceSerialNumberLength: 0
DeviceSerialNumber: ''
BusType: 10
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
DurationUs: 49
InputFlags: '0x10'
Reason: 7
Flags: '0x10'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10 — NTFS cached runs statistics.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeId | Volume name. |
VolumeLabel | — |
DeviceName | — |
DeviceGuid | — |
VendorId | Device manufacturer. |
ProductId | Device model. |
ProductRevision | Device revision. |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumber | — |
MediaType | Capacity tier name. |
RunsCached | Media type. |
LongestRunCached | Runs cached. |
LongestRunCachedStr | — |
MostPopulatedBinCount | Longest run cached. |
MostPopulatedBinMinLength | Most populated bin Count. |
MostPopulatedBinMinLengthStr | — |
MostPopulatedBinMaxLength | Most populated bin's minimum length. |
MostPopulatedBinMaxLengthStr | — |
TotalCachedRuns | Most populated bin's maximum length. |
CachedRunsLogged | — |
CachedRunsAlignment | — |
RunsInCachedRuns | — |
LongestRunInCachedRuns | — |
MostPopulatedBinCountInCachedRuns | — |
MostPopulatedBinMinLengthInCachedRuns | — |
MostPopulatedBinMaxLengthInCachedRuns | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 10
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018429485056
time_created: '2023-11-06T06:25:25.774232+00:00'
event_record_id: 150
correlation: {}
execution:
process_id: 4
thread_id: 108
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: F8B2740A-2324-44DB-BBF8-80523FE5334B
VolumeId: \\?\Volume{f8b2740a-2324-44db-bbf8-80523fe5334b}
VolumeLabel: WINRE
DeviceName: \Device\HarddiskVolume1
DeviceGuid: 33A0A150-7C6D-11EE-9369-806E6F6E6963
VendorId: 'VMware, '
ProductId: VMware Virtual S
ProductRevision: '1.0 '
DeviceSerialNumber: ''
BusType: 10
AdapterSerialNumber: ''
MediaType: 1
RunsCached: 3
LongestRunCached: 209448960
LongestRunCachedStr: 199.75 MB
MostPopulatedBinCount: 1
MostPopulatedBinMinLength: 2363392
MostPopulatedBinMinLengthStr: 2.26 MB
MostPopulatedBinMaxLength: 2490368
MostPopulatedBinMaxLengthStr: 2.38 MB
TotalCachedRuns: 1
CachedRunsLogged: 1
CachedRunsAlignment: '1'
RunsInCachedRuns: '3'
LongestRunInCachedRuns: '209448960'
MostPopulatedBinCountInCachedRuns: '1'
MostPopulatedBinMinLengthInCachedRuns: '2363392'
MostPopulatedBinMaxLengthInCachedRuns: '2490368'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 11 — NTFS KSR data prepared successfully.
Message
Fields
| Name | Description |
|---|---|
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
Version | — |
CachedRunsPreparedRunCount | — |
CachedRunsPreparedTimeMs | — |
Event ID 12 — NTFS KSR data prepare failed.
Message
Fields
| Name | Description |
|---|---|
Device_Name | — |
Volume_GUID | — |
Error | Device Name. |
Failure_Status | Volume GUID. |
Source_Tag | — |
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
MessageLength | — |
Message | — |
FailureStatus | — |
SourceTag | — |
Event ID 13 — NTFS KSR data filled successfully.
Message
Fields
| Name | Description |
|---|---|
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
Version | — |
CachedRunsFilledRunCount | — |
CachedRunsFilledTimeMs | — |
Event ID 14 — NTFS KSR data fill failed.
Message
Fields
| Name | Description |
|---|---|
Device_Name | — |
Volume_GUID | — |
Error | Device Name. |
Failure_Status | Volume GUID. |
Source_Tag | — |
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
MessageLength | — |
Message | — |
FailureStatus | — |
SourceTag | — |
Event ID 98 — Volume %1 (%2) %3.
Message
Fields
| Name | Description |
|---|---|
DriveName | — |
DeviceName | — |
CorruptionActionState | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 98
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775810
time_created: '2023-11-06T06:25:20.848748+00:00'
event_record_id: 1651
correlation: {}
execution:
process_id: 4
thread_id: 96
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
DriveName: \\?\Volume{f8b2740a-2324-44db-bbf8-80523fe5334b}
DeviceName: \Device\HarddiskVolume1
CorruptionActionState: 0
message: ''
Sigma Rules
- Volume Shadow Copy Mount
Detects volume shadow copy mount via Windows event log
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 100 — NTFS global corruption action state is now %1.
Message
Fields
| Name | Description |
|---|---|
hc_stateid | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 100
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693953
time_created: '2023-11-06T06:25:12.106652+00:00'
event_record_id: 11
correlation: {}
execution:
process_id: 4
thread_id: 8
channel: Microsoft-Windows-Ntfs/WHC
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
hc_stateid: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 139 — The file system structure that maintains security information on volume %1 (%2) has grown excessively large and fragmented.
Message
Fields
| Name | Description |
|---|---|
DriveName | — |
DeviceName | — |
FragmentationLevel | — |
Event ID 140 — The system failed to flush data to the transaction log.
Message
Fields
| Name | Description |
|---|---|
VolumeIdLength | — |
VolumeId | — |
DeviceNameLength | — |
DeviceName | The system failed to flush data to the transaction log. Corruption may occur in VolumeId. |
Error | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Event ID 141 — An operation failed because the disk was full.
Message
Fields
| Name | Description |
|---|---|
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
ProcessNameLength | — |
ProcessName | — |
IsBootVolume | — |
FreeSpaceInBytes | — |
TotalReservedSpaceInBytes | — |
TotalAbortReservationSpaceInBytes | — |
RequestedSpaceInBytes | — |
PageFileSize | — |
SourceTag | — |
Event ID 142 — Summary of disk space usage, since last event: Lowest free space in bytes: %4 Highest free space in bytes: %5 Page file size in bytes: 0 Volume gui...
Message
Fields
| Name | Description |
|---|---|
VolumeGuid | [Summary of disk space usage, since last event] Volume guid. |
VolumeNameLength | — |
VolumeName | [Summary of disk space usage, since last event] Volume name. |
IsBootVolume | [Summary of disk space usage, since last event] Is boot volume. |
ElapsedSeconds | [Summary of disk space usage, since last event] Elapsed seconds. |
AvailabeSpaceMinStr | — |
AvailabeSpaceMaxStr | — |
AvailabeSpaceDeltaStr | [Summary of disk space usage, since last event] Change in available space. |
AvailableClustersMin | [Summary of disk space usage, since last event] Available clusters were between. |
AvailableClustersMax | — |
UnallocatedClustersMin | — |
UnallocatedClustersMax | — |
ReservedClustersMin | [Summary of disk space usage, since last event] Reserved clusters were between. |
ReservedClustersMax | — |
TxfAbortReservedClustersMin | [Summary of disk space usage, since last event] Txf abort reserved clusters were between. |
TxfAbortReservedClustersMax | — |
PageFileSizeInBytes | — |
PageFileSizeStr | [Summary of disk space usage, since last event] Pagefile size. |
VolumeSizeInBytes | — |
VolumeSizeStr | [Summary of disk space usage, since last event] Volume size. |
ClusterSize | [Summary of disk space usage, since last event] Bytes per cluster. |
CachedRunsMissCountForMft | — |
CachedRunsMissCountForMftZone | [Summary of disk space usage, since last event] Slab size. |
CachedRunsMissCount | [Summary of disk space usage, since last event] Slabs in use. |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 142
version: 3
level: 4
task: 0
opcode: 0
keywords: 4611686018429485056
time_created: '2023-11-06T06:25:25.734659+00:00'
event_record_id: 148
correlation: {}
execution:
process_id: 4
thread_id: 108
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeGuid: F8B2740A-2324-44DB-BBF8-80523FE5334B
VolumeNameLength: 48
VolumeName: \\?\Volume{f8b2740a-2324-44db-bbf8-80523fe5334b}
IsBootVolume: false
ElapsedSeconds: 0
AvailabeSpaceMinStr: 287.18 MB
AvailabeSpaceMaxStr: 291.18 MB
AvailabeSpaceDeltaStr: 4 MB
AvailableClustersMin: 73518
AvailableClustersMax: 74542
UnallocatedClustersMin: 74542
UnallocatedClustersMax: 74542
ReservedClustersMin: 0
ReservedClustersMax: 0
TxfAbortReservedClustersMin: 1024
TxfAbortReservedClustersMax: 1024
PageFileSizeInBytes: 0
PageFileSizeStr: 0 Bytes
VolumeSizeInBytes: 314568704
VolumeSizeStr: 300 MB
ClusterSize: 4096
CachedRunsMissCountForMft: 0
CachedRunsMissCountForMftZone: 0
CachedRunsMissCount: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 143 — Surprise removal of a persistent memory device with active DAX mappings.
Message
Fields
| Name | Description |
|---|---|
Volume_GUID | — |
Volume_Name | — |
Volume_Label | — |
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
VolumeLabelLength | — |
VolumeLabel | — |
Event ID 144 — A volume that already has DAX mappings is being mounted.
Message
Fields
| Name | Description |
|---|---|
Volume_GUID | — |
Volume_Name | — |
Vcb | — |
DeviceNameLength | — |
DeviceName | — |
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
Event ID 145 — IO latency summary common data for volume: Volume Id: %2 Volume name: %4 Is boot volume: %5 Device GUID: %7 Device manufacturer: %9 Device model: %...
Message
Fields
| Name | Description |
|---|---|
Version | — |
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
TierIndex | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
MaxLatencyMs | — |
ReadWriteLatencyBucket1 | — |
ReadWriteLatencyBucket2 | — |
ReadWriteLatencyBucket3 | — |
ReadWriteLatencyBucket4 | — |
ReadWriteLatencyBucket5 | — |
ReadWriteLatencyBucket6 | — |
ReadWriteLatencyBucket7 | — |
TrimLatencyBucket1 | — |
TrimLatencyBucket2 | — |
TrimLatencyBucket3 | — |
TrimLatencyBucket4 | — |
TrimLatencyBucket5 | — |
TrimLatencyBucket6 | — |
TrimLatencyBucket7 | — |
FlushLatencyBucket1 | — |
FlushLatencyBucket2 | — |
FlushLatencyBucket3 | — |
FlushLatencyBucket4 | — |
FlushLatencyBucket5 | — |
FlushLatencyBucket6 | — |
FlushLatencyBucket7 | — |
Event ID 146 — IO latency summary: Volume Id: %2 Volume name: %4 Is boot volume: %5 Device GUID: %7 Device manufacturer: %9 Device model: %11 Device revision: %13...
Message
Fields
| Name | Description |
|---|---|
Version | — |
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
TierIndex | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
MaxLatencyMs | — |
ReadWriteLatencyBucket1 | — |
ReadWriteLatencyBucket2 | — |
ReadWriteLatencyBucket3 | — |
ReadWriteLatencyBucket4 | — |
ReadWriteLatencyBucket5 | — |
ReadWriteLatencyBucket6 | — |
ReadWriteLatencyBucket7 | — |
TrimLatencyBucket1 | — |
TrimLatencyBucket2 | — |
TrimLatencyBucket3 | — |
TrimLatencyBucket4 | — |
TrimLatencyBucket5 | — |
TrimLatencyBucket6 | — |
TrimLatencyBucket7 | — |
FlushLatencyBucket1 | — |
FlushLatencyBucket2 | — |
FlushLatencyBucket3 | — |
FlushLatencyBucket4 | — |
FlushLatencyBucket5 | — |
FlushLatencyBucket6 | — |
FlushLatencyBucket7 | — |
HighIoLatencyCount | — |
IntervalDurationUs | — |
NCReadIOCount | — |
NCReadTotalBytes | — |
NCReadAvgLatencyNs | — |
NCWriteIOCount | — |
NCWriteTotalBytes | — |
NCWriteAvgLatencyNs | — |
FileFlushCount | — |
FileFlushAvgLatencyNs | — |
DirectoryFlushCount | — |
DirectoryFlushAvgLatencyNs | — |
VolumeFlushCount | — |
VolumeFlushAvgLatencyNs | — |
FileLevelTrimCount | — |
FileLevelTrimTotalBytes | — |
FileLevelTrimExtentsCount | — |
FileLevelTrimAvgLatencyNs | — |
VolumeTrimCount | — |
VolumeTrimTotalBytes | — |
VolumeTrimExtentsCount | — |
VolumeTrimAvgLatencyNs | — |
IoBucketsCount | — |
TotalBytesBucketsCount | — |
ExtentsBucketsCount | — |
IoCount | — |
TotalLatencyUs | — |
TotalBytes | — |
TrimExtentsCount | — |
IoTypeIndex | — |
VcbExAcquireCount | — |
VcbExMaxWaitDurationMs | — |
VcbExAvgWaitDurationMs | — |
VcbExMaxHoldDurationMs | — |
VcbExAvgHoldDurationMs | — |
VcbExMaxCombinedDurationMs | — |
VcbExAvgCombinedDurationMs | — |
Event ID 147 — An IO took more than %5 ms to complete: Process Id: %6 Process name: %7 File name: %9 File offset: %12 IO Type: %10 IO Size: %11 bytes %15 cluster.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | Volume Id. |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
MaxLatencyMs | — |
ProcessId | — |
ProcessName | — |
FileNameLength | — |
FileName | — |
FileIdHigh | — |
FileIdLow | — |
IoType | — |
IoTypeStr | IO Type. |
IoSize | Latency. |
FileOffset | Device GUID. |
LatencyMs | — |
StartingLcn | Device manufacturer. |
ClustersCount | — |
DeviceGuid | Device model. |
VendorIdLength | — |
VendorId | Device revision. |
ProductIdLength | — |
ProductId | Device serial number. |
ProductRevisionLength | Bus type. |
ProductRevision | — |
DeviceSerialNumberLength | Adapter serial number. |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 147
version: 4
level: 3
task: 0
opcode: 0
keywords: 4611967493406195712
time_created: '2023-11-06T01:29:13.914837+00:00'
event_record_id: 229
correlation: {}
execution:
process_id: 4
thread_id: 17620
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: 7597D2A3-4404-4F99-B979-6233378A81BF
VolumeNameLength: 2
VolumeName: 'C:'
IsBootVolume: true
MaxLatencyMs: 30000
ProcessId: 18984
ProcessName: MBAMService.ex
FileNameLength: 74
FileName: \ProgramData\Malwarebytes\MBAMService\tmp\cde8f2247c4311ee8e26000c293379ba
FileIdHigh: '0x0'
FileIdLow: '0x200000004f2d1'
IoType: 5
IoTypeStr: 'Write: NonPaging, Cached, Sync'
IoSize: 23213552
FileOffset: 0
LatencyMs: 38428
StartingLcn: 15120321
ClustersCount: 5668
DeviceGuid: 22A04354-7C2B-11EE-936C-806E6F6E6963
VendorIdLength: 8
VendorId: 'VMware, '
ProductIdLength: 16
ProductId: VMware Virtual S
ProductRevisionLength: 4
ProductRevision: '1.0 '
DeviceSerialNumberLength: 0
DeviceSerialNumber: ''
BusType: 10
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 148 — A %9 failed with %14.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
ProcessId | — |
ProcessName | — |
FileNameLength | — |
FileName | — |
FileIdHigh | — |
FileIdLow | — |
IoType | — |
IoSize | — |
FileOffset | — |
StartingLcn | — |
ClustersCount | — |
FailureStatus | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
NativeNVMe | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Event ID 149 — In the past %17 seconds we had high latency IOs and/or IO failures.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | Volume Id. |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | Device manufacturer. |
ProductIdLength | — |
ProductId | Device model. |
ProductRevisionLength | — |
ProductRevision | Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
SecondsElapsed | — |
HighLatencyCount | High latency IO count. |
FailedWriteCount | Failed writes. |
FailedReadCount | Failed reads. |
BadClusterHotfixCount | Bad clusters relocated. |
ValuesCount | — |
HighLatencyArray | — |
FailedWriteArray | — |
FailedReadArray | — |
BadClusterHotfixArray | — |
StatusArray | — |
TableIndexArray | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 149
version: 2
level: 3
task: 0
opcode: 0
keywords: 4611967493406195712
time_created: '2023-11-06T01:32:12.814212+00:00'
event_record_id: 249
correlation: {}
execution:
process_id: 4
thread_id: 18088
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: 7597D2A3-4404-4F99-B979-6233378A81BF
VolumeNameLength: 2
VolumeName: 'C:'
IsBootVolume: true
DeviceGuid: 22A04354-7C2B-11EE-936C-806E6F6E6963
VendorIdLength: 8
VendorId: 'VMware, '
ProductIdLength: 16
ProductId: VMware Virtual S
ProductRevisionLength: 4
ProductRevision: '1.0 '
DeviceSerialNumberLength: 0
DeviceSerialNumber: ''
BusType: 10
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
SecondsElapsed: 3602
HighLatencyCount: 4
FailedWriteCount: 0
FailedReadCount: 0
BadClusterHotfixCount: 0
ValuesCount: 3
HighLatencyArray: 1
FailedWriteArray: 0
FailedReadArray: 0
BadClusterHotfixArray: 0
StatusArray: '0x0'
TableIndexArray: 3
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 150 — An IO failed with %12 and NTFS has relocated the clusters.
Message
Fields
| Name | Description |
|---|---|
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
ProcessId | — |
ProcessName | — |
FileNameLength | — |
FileName | — |
BadFileOffset | — |
BadLcn | — |
ClustersCount | — |
FailureStatus | — |
Event ID 151 — In the past %5 seconds %6 files were deleted from the user's popular known folders.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
SecondsElapsed | — |
TotalCountDeleteFile | — |
TotalCountDeleteFileLogged | — |
ProcessNamesArray | — |
CountDeletesInDesktopArray | — |
CountDeletesInDocumentsArray | — |
CountDeletesInDownloadsArray | — |
CountDeletesInMusicArray | — |
CountDeletesInPicturesArray | — |
CountDeletesInVideosArray | — |
CountDeletesInOtherArray | — |
Event ID 152 — A process has not acknowledged an NTFS oplock break in a long time.
Message
Fields
| Name | Description |
|---|---|
Time_seconds | Time (seconds). |
Owner_Process | — |
Breaking_Process | — |
TimeoutSeconds | — |
OwnerProcessNameLength | — |
OwnerProcessName | — |
BreakingProcessNameLength | — |
BreakingProcessName | — |
Event ID 154 — System file pages are now locked into memory.
Message
Fields
| Name | Description |
|---|---|
Volume_Id | — |
Volume_name | — |
File_reference | — |
File_name | — |
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
FileReference | — |
FileNameLength | — |
FileName | — |
Event ID 155 — System file pages are no longer locked into memory.
Message
Fields
| Name | Description |
|---|---|
Volume_Id | — |
Volume_name | — |
File_reference | — |
File_name | — |
Reason | — |
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
FileReference | — |
FileNameLength | — |
FileName | — |
UnlockReason | — |
Event ID 156 — VCB exclusive resource acquires: Volume Id: %1 Volume name: %3 Is boot volume: %4 Interval duration: %18 Acquire count: %19 Max wait duration: %20 ...
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | [VCB exclusive resource acquires] Volume Id. |
VolumeNameLength | — |
VolumeName | [VCB exclusive resource acquires] Volume name. |
IsBootVolume | [VCB exclusive resource acquires] Is boot volume. |
DeviceGuid | [VCB exclusive resource acquires] Device GUID. |
VendorIdLength | — |
VendorId | [VCB exclusive resource acquires] Device manufacturer. |
ProductIdLength | — |
ProductId | [VCB exclusive resource acquires] Device model. |
ProductRevisionLength | — |
ProductRevision | [VCB exclusive resource acquires] Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | [VCB exclusive resource acquires] Device serial number. |
BusType | [VCB exclusive resource acquires] Bus type. |
AdapterSerialNumberLength | — |
AdapterSerialNumber | [VCB exclusive resource acquires] Adapter serial number. |
IntervalDurationMs | — |
IntervalDurationStr | [VCB exclusive resource acquires] Interval duration. |
VcbExAcquireCount | [VCB exclusive resource acquires] Acquire count. |
VcbExMaxWaitDurationMs | [VCB exclusive resource acquires] Max wait duration. |
VcbExAvgWaitDurationMs | [VCB exclusive resource acquires] Avg wait duration. |
VcbExMaxHoldDurationMs | [VCB exclusive resource acquires] Max hold duration. |
VcbExAvgHoldDurationMs | [VCB exclusive resource acquires] Avg hold duration. |
VcbExMaxCombinedDurationMs | [VCB exclusive resource acquires] Max combined duration. |
VcbExAvgCombinedDurationMs | [VCB exclusive resource acquires] Avg combined duration. |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 156
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018429485056
time_created: '2023-11-06T01:32:12.811781+00:00'
event_record_id: 230
correlation: {}
execution:
process_id: 4
thread_id: 18088
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: 7597D2A3-4404-4F99-B979-6233378A81BF
VolumeNameLength: 2
VolumeName: 'C:'
IsBootVolume: true
DeviceGuid: 22A04354-7C2B-11EE-936C-806E6F6E6963
VendorIdLength: 8
VendorId: 'VMware, '
ProductIdLength: 16
ProductId: VMware Virtual S
ProductRevisionLength: 4
ProductRevision: '1.0 '
DeviceSerialNumberLength: 0
DeviceSerialNumber: ''
BusType: 10
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
IntervalDurationMs: 3602451
IntervalDurationStr: 3602 s
VcbExAcquireCount: 171
VcbExMaxWaitDurationMs: 15210
VcbExAvgWaitDurationMs: 90
VcbExMaxHoldDurationMs: 18627
VcbExAvgHoldDurationMs: 237
VcbExMaxCombinedDurationMs: 18627
VcbExAvgCombinedDurationMs: 327
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 157 — An exclusive resource duration exceeded %5 ms: Process Id: %6 Process name: %7 Major function: %8 Minor function: %9 Control code: %10 Resource nam...
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
IsBootVolume | — |
MaxDurationMs | — |
ProcessId | — |
ProcessName | — |
MajorFunction | — |
MinorFunction | — |
ControlCode | — |
ResourceName | — |
WaitDurationMs | — |
HoldDurationMs | — |
CombinedDurationMs | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
NativeNVMe | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Event ID 158 — NTFS metadata statistics for volume: Volume Id: %1 Volume name: %3 UserFileReads: %4 UserFileReadBytes: %5 UserDiskReads: %6 UserFileWrites: %7 Use...
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | [NTFS metadata statistics for volume] Volume Id. |
VolumeNameLength | — |
VolumeName | [NTFS metadata statistics for volume] Volume name. |
UserFileReads | [NTFS metadata statistics for volume] UserFileReads. |
UserFileReadBytes | [NTFS metadata statistics for volume] UserFileReadBytes. |
UserDiskReads | [NTFS metadata statistics for volume] UserDiskReads. |
UserFileWrites | [NTFS metadata statistics for volume] UserFileWrites. |
UserFileWriteBytes | [NTFS metadata statistics for volume] UserFileWriteBytes. |
UserDiskWrites | [NTFS metadata statistics for volume] UserDiskWrites. |
MetaDataReads | [NTFS metadata statistics for volume] MetaDataReads. |
MetaDataReadBytes | [NTFS metadata statistics for volume] MetaDataReadBytes. |
MetaDataDiskReads | [NTFS metadata statistics for volume] MetaDataDiskReads. |
MetaDataWrites | [NTFS metadata statistics for volume] MetaDataWrites. |
MetaDataWriteBytes | [NTFS metadata statistics for volume] MetaDataWriteBytes. |
MetaDataDiskWrites | [NTFS metadata statistics for volume] MetaDataDiskWrites. |
MftReads | [NTFS metadata statistics for volume] MftReads. |
MftReadBytes | [NTFS metadata statistics for volume] MftReadBytes. |
MftWrites | [NTFS metadata statistics for volume] MftWrites. |
MftWriteBytes | [NTFS metadata statistics for volume] MftWriteBytes. |
Mft2Writes | [NTFS metadata statistics for volume] Mft2Writes. |
Mft2WriteBytes | [NTFS metadata statistics for volume] Mft2WriteBytes. |
RootIndexReads | [NTFS metadata statistics for volume] RootIndexReads. |
RootIndexReadBytes | [NTFS metadata statistics for volume] RootIndexReadBytes. |
RootIndexWrites | [NTFS metadata statistics for volume] RootIndexWrites. |
RootIndexWriteBytes | [NTFS metadata statistics for volume] RootIndexWriteBytes. |
BitmapReads | [NTFS metadata statistics for volume] BitmapReads. |
BitmapReadBytes | [NTFS metadata statistics for volume] BitmapReadBytes. |
BitmapWrites | [NTFS metadata statistics for volume] BitmapWrites. |
BitmapWriteBytes | [NTFS metadata statistics for volume] BitmapWriteBytes. |
MftBitmapReads | [NTFS metadata statistics for volume] MftBitmapReads. |
MftBitmapReadBytes | [NTFS metadata statistics for volume] MftBitmapReadBytes. |
MftBitmapWrites | [NTFS metadata statistics for volume] MftBitmapWrites. |
MftBitmapWriteBytes | [NTFS metadata statistics for volume] MftBitmapWriteBytes. |
UserIndexReads | [NTFS metadata statistics for volume] UserIndexReads. |
UserIndexReadBytes | [NTFS metadata statistics for volume] UserIndexReadBytes. |
UserIndexWrites | [NTFS metadata statistics for volume] UserIndexWrites. |
UserIndexWriteBytes | [NTFS metadata statistics for volume] UserIndexWriteBytes. |
LogFileReads | [NTFS metadata statistics for volume] LogFileReads. |
LogFileReadBytes | [NTFS metadata statistics for volume] LogFileReadBytes. |
LogFileWrites | [NTFS metadata statistics for volume] LogFileWrites. |
LogFileWriteBytes | [NTFS metadata statistics for volume] LogFileWriteBytes. |
LogFileFull | [NTFS metadata statistics for volume] LogFileFull. |
LogFileFullReasonBucket1 | [LogFileFullReasons] LF_LOG_SPACE. |
LogFileFullReasonBucket2 | [LogFileFullReasons] LF_DIRTY_PAGES. |
LogFileFullReasonBucket3 | [LogFileFullReasons] LF_OPEN_ATTRIBUTES. |
LogFileFullReasonBucket4 | [LogFileFullReasons] LF_TRANSACTION_DRAIN. |
LogFileFullReasonBucket5 | [LogFileFullReasons] LF_FASTIO_CALLBACK. |
LogFileFullReasonBucket6 | [LogFileFullReasons] LF_DEALLOCATED_CLUSTERS. |
LogFileFullReasonBucket7 | [LogFileFullReasons] LF_DEALLOCATED_CLUSTERS_MEM. |
LogFileFullReasonBucket8 | [LogFileFullReasons] LF_RECORD_STACK_CHECK. |
LogFileFullReasonBucket9 | [LogFileFullReasons] LF_DISMOUNT. |
LogFileFullReasonBucket10 | [LogFileFullReasons] LF_COMPRESSION. |
LogFileFullReasonBucket11 | [LogFileFullReasons] LF_SNAPSHOT. |
LogFileFullReasonBucket12 | [LogFileFullReasons] LF_MOUNT. |
LogFileFullReasonBucket13 | [LogFileFullReasons] LF_SHUTDOWN. |
LogFileFullReasonBucket14 | [LogFileFullReasons] LF_RECURSIVE_COMPRESSION. |
LogFileFullReasonBucket15 | [LogFileFullReasons] LF_TESTING. |
DiskResourceFailure | [LogFileFullReasons] DiskResourceFailure. |
VolumeTrimCount | [LogFileFullReasons] VolumeTrimCount. |
VolumeTrimTime | [LogFileFullReasons] VolumeTrimTime (ms). |
VolumeTrimSize | [LogFileFullReasons] VolumeTrimSize (KB). |
AvgVolumeTrimTime | [LogFileFullReasons] AvgVolumeTrimTime (ms). |
AvgVolumeTrimSize | [LogFileFullReasons] AvgVolumeTrimSize (KB). |
VolumeTrimSkippedCount | [LogFileFullReasons] VolumeTrimSkippedCount. |
VolumeTrimSkippedSize | [LogFileFullReasons] VolumeTrimSkippedSize (KB). |
FileLevelTrimCount | [LogFileFullReasons] FileLevelTrimCount. |
FileLevelTrimTime | [LogFileFullReasons] FileLevelTrimTime (ms). |
FileLevelTrimSize | [LogFileFullReasons] FileLevelTrimSize (KB). |
AvgFileLevelTrimTime | [LogFileFullReasons] AvgFileLevelTrimTime (ms). |
AvgFileLevelTrimSize | [LogFileFullReasons] AvgFileLevelTrimSize (KB). |
NtfsFillStatInfoFromMftRecordCalledCount | [LogFileFullReasons] NtfsFillStatInfoFromMftRecordCalledCount. |
NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount | [LogFileFullReasons] NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount. |
NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount | [LogFileFullReasons] NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount. |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 158
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018429485056
time_created: '2023-11-05T22:47:04.964890+00:00'
event_record_id: 183
correlation: {}
execution:
process_id: 4
thread_id: 52
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: F8B2740A-2324-44DB-BBF8-80523FE5334B
VolumeNameLength: 48
VolumeName: \\?\Volume{f8b2740a-2324-44db-bbf8-80523fe5334b}
UserFileReads: 5
UserFileReadBytes: 20480
UserDiskReads: 5
UserFileWrites: 0
UserFileWriteBytes: 0
UserDiskWrites: 0
MetaDataReads: 12
MetaDataReadBytes: 217088
MetaDataDiskReads: 14
MetaDataWrites: 1
MetaDataWriteBytes: 8192
MetaDataDiskWrites: 2
MftReads: 6
MftReadBytes: 53248
MftWrites: 1
MftWriteBytes: 8192
Mft2Writes: 0
Mft2WriteBytes: 0
RootIndexReads: 0
RootIndexReadBytes: 0
RootIndexWrites: 0
RootIndexWriteBytes: 0
BitmapReads: 1
BitmapReadBytes: 12288
BitmapWrites: 0
BitmapWriteBytes: 0
MftBitmapReads: 1
MftBitmapReadBytes: 8192
MftBitmapWrites: 0
MftBitmapWriteBytes: 0
UserIndexReads: 1
UserIndexReadBytes: 4096
UserIndexWrites: 1
UserIndexWriteBytes: 4096
LogFileReads: 8
LogFileReadBytes: 32768
LogFileWrites: 16
LogFileWriteBytes: 65536
LogFileFull: 0
LogFileFullReasonBucket1: 0
LogFileFullReasonBucket2: 0
LogFileFullReasonBucket3: 0
LogFileFullReasonBucket4: 0
LogFileFullReasonBucket5: 0
LogFileFullReasonBucket6: 0
LogFileFullReasonBucket7: 0
LogFileFullReasonBucket8: 0
LogFileFullReasonBucket9: 0
LogFileFullReasonBucket10: 0
LogFileFullReasonBucket11: 0
LogFileFullReasonBucket12: 0
LogFileFullReasonBucket13: 0
LogFileFullReasonBucket14: 0
LogFileFullReasonBucket15: 0
DiskResourceFailure: 0
VolumeTrimCount: 0
VolumeTrimTime: 0
VolumeTrimSize: 0
AvgVolumeTrimTime: 0
AvgVolumeTrimSize: 0
VolumeTrimSkippedCount: 0
VolumeTrimSkippedSize: 0
FileLevelTrimCount: 0
FileLevelTrimTime: 0
FileLevelTrimSize: 0
AvgFileLevelTrimTime: 0
AvgFileLevelTrimSize: 0
NtfsFillStatInfoFromMftRecordCalledCount: 0
NtfsFillStatInfoFromMftRecordBailedBecauseOfAttributeListCount: 0
NtfsFillStatInfoFromMftRecordBailedBecauseOfNonResReparsePointCount: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 159 — NTFS has successfully completed the %19 request in %20 ms when trying to %18 the volume size from %4 (MB) to %5 (MB).
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | Volume Id. |
VolumeNameLength | — |
VolumeName | — |
FromSize | — |
ToSize | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | Device manufacturer. |
ProductIdLength | — |
ProductId | Device model. |
ProductRevisionLength | — |
ProductRevision | Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
VolumeSizeChangeOperation | Operation. |
VolumeSizeChangeRequestType | Request Type. |
CombinedDurationMs | — |
Stage1DurationMs | [Stage Durations] Stage 1. Verify input and calculate new volume size (ms). |
Stage2DurationMs | [Stage Durations] Stage 2. Set boundary and allocate/deallocate cluster (ms). |
Stage3DurationMs | [Stage Durations] Stage 3. Update bitmap (ms). |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 159
version: 0
level: 4
task: 13
opcode: 0
keywords: 4611686018429485056
time_created: '2022-04-07T16:45:03.658483+00:00'
event_record_id: 8
correlation: {}
execution:
process_id: 4476
thread_id: 4512
channel: Microsoft-Windows-Ntfs/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: ADDC92DC-EB36-4896-AAEB-9547FEEB7B8C
VolumeNameLength: 2
VolumeName: 'C:'
FromSize: 102281
ToSize: 101756
DeviceGuid: 7B6F1752-BD95-6E22-E3A5-6EE8419ECAD7
VendorIdLength: 0
VendorId: ''
ProductIdLength: 24
ProductId: VMware Virtual NVMe Disk
ProductRevisionLength: 3
ProductRevision: '1.0'
DeviceSerialNumberLength: 16
DeviceSerialNumber: VMWare NVME_0000
BusType: 17
AdapterSerialNumberLength: 16
AdapterSerialNumber: VMWare NVME_0000
VolumeSizeChangeOperation: 1
VolumeSizeChangeRequestType: 2
CombinedDurationMs: 62
Stage1DurationMs: 0
Stage2DurationMs: 0
Stage3DurationMs: 62
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 160 — NTFS has failed to complete the %19 request after %20 ms when trying to %18 the volume size from %4 (MB) to %5 (MB).
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
FromSize | — |
ToSize | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
NativeNVMe | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
VolumeSizeChangeOperation | — |
VolumeSizeChangeRequestType | — |
CombinedDurationMs | — |
Stage1DurationMs | — |
Stage2DurationMs | — |
Stage3DurationMs | — |
FailureStage | — |
FailureStatusCode | — |
FailureReason | — |
Event ID 161 — An operation has failed due to a file system limitation.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Volume_Id | — |
Volume_Name | — |
File_Path | — |
ReasonOrigin | — |
VolumeCorrelationId | — |
VolumeName | — |
FilePath | — |
AdditionalInfo | — |
Event ID 162 — The data read from the storage does not match what was previously written or read.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | — |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
FileReference | — |
FileNameLength | — |
FileName | — |
AttributeTypeCode | — |
AttributeNameLength | — |
AttributeName | — |
FileOffset | — |
VolumeOffset | — |
Length | — |
CalledFromWorker | — |
WorkerStatus | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
NativeNVMe | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
ReadDataValidOffset | — |
ReadDataValidLength | — |
ReadData | — |
PrevDataValidOffset | — |
PrevDataValidLength | — |
PrevData | — |
Event ID 163 — MftBitmap is not big enough for MftData or does not have required allocations.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | — |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
NativeNVMe | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
MftDataAllocationSize | — |
MftDataFileSize | — |
MftBitmapAllocationSize | — |
MftBitmapFileSize | — |
BytesPerFRS | — |
MftDataAttrAllocatedLength | — |
MftDataAttrFileSize | — |
MftBitmapAttrHighestVcn | — |
MftBitmapAttrAllocatedLength | — |
MftBitmapAttrFileSize | — |
MftLastDataAndBitmapInSameFrs | — |
CalledFromWorker | — |
WorkerStatus | — |
MajorFunction | — |
MinorFunction | — |
SourceTag | — |
Event ID 170 — IO latency summary: Volume Id: %1 Volume name: %3 Is boot volume: %4 IO type: %20 Interval duration: %18 Max Acceptable IO Latency: %22 High Latenc...
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | [IO latency summary] Volume Id. |
VolumeNameLength | — |
VolumeName | [IO latency summary] Volume name. |
IsBootVolume | [IO latency summary] Is boot volume. |
DeviceGuid | [IO latency summary] Device GUID. |
VendorIdLength | — |
VendorId | [IO latency summary] Device manufacturer. |
ProductIdLength | — |
ProductId | [IO latency summary] Device model. |
ProductRevisionLength | — |
ProductRevision | [IO latency summary] Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | [IO latency summary] Device serial number. |
BusType | [IO latency summary] Bus type. |
AdapterSerialNumberLength | — |
AdapterSerialNumber | [IO latency summary] Adapter serial number. |
IntervalDurationMs | — |
IntervalDurationStr | [IO latency summary] Interval duration. |
SummaryId | — |
IoType | — |
IoTypeStr | [IO latency summary] IO type. |
HighLatencyMs | — |
HighLatencyStr | [IO latency summary] Max Acceptable IO Latency. |
HighLatencyIoCount | [IO latency summary] High Latency IOs. |
TotalIoCount | [IO latency summary] IO count. |
TotalIoTimeNs | — |
AverageIops | [IO latency summary] Avg IOPS. |
AverageLatencyNs | — |
AverageLatencyStr | [IO latency summary] Avg latency. |
MaxLatencyNs | — |
MaxLatencyStr | [IO latency summary] Max latency. |
LatencyBuckets | — |
IoCount0 | — |
IoCount1 | — |
IoCount2 | — |
IoCount3 | — |
IoCount4 | — |
IoCount5 | — |
IoCount6 | — |
IoCount7 | — |
IoCount8 | — |
IoCount9 | — |
IoCount10 | — |
IoCount11 | — |
IoCount12 | — |
IoCount13 | — |
IoCount14 | — |
IoCount15 | — |
TotalTimeNs0 | — |
TotalTimeNs1 | — |
TotalTimeNs2 | — |
TotalTimeNs3 | — |
TotalTimeNs4 | — |
TotalTimeNs5 | — |
TotalTimeNs6 | — |
TotalTimeNs7 | — |
TotalTimeNs8 | — |
TotalTimeNs9 | — |
TotalTimeNs10 | — |
TotalTimeNs11 | — |
TotalTimeNs12 | — |
TotalTimeNs13 | — |
TotalTimeNs14 | — |
TotalTimeNs15 | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 170
version: 4
level: 4
task: 0
opcode: 0
keywords: 4611967493406195712
time_created: '2023-11-06T01:32:12.811964+00:00'
event_record_id: 248
correlation: {}
execution:
process_id: 4
thread_id: 18088
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: 7597D2A3-4404-4F99-B979-6233378A81BF
VolumeNameLength: 2
VolumeName: 'C:'
IsBootVolume: true
DeviceGuid: 22A04354-7C2B-11EE-936C-806E6F6E6963
VendorIdLength: 8
VendorId: 'VMware, '
ProductIdLength: 16
ProductId: VMware Virtual S
ProductRevisionLength: 4
ProductRevision: '1.0 '
DeviceSerialNumberLength: 0
DeviceSerialNumber: ''
BusType: 10
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
IntervalDurationMs: 3602451
IntervalDurationStr: 3602 s
SummaryId: 108174105061
IoType: 29
IoTypeStr: Allocate clusters
HighLatencyMs: 30000
HighLatencyStr: 30 s
HighLatencyIoCount: 0
TotalIoCount: 48922
TotalIoTimeNs: 14280377600
AverageIops: 3426
AverageLatencyNs: 291900
AverageLatencyStr: 291 µs
MaxLatencyNs: 5739679000
MaxLatencyStr: 5 s
LatencyBuckets: 128 µs, 256 µs, 512 µs, 1 ms, 4 ms, 16 ms, 64 ms, 128 ms, 256 ms,
512 ms, 1 s, 2 s, 10 s, 20 s, 30 s, > 30 s
IoCount0: 44799
IoCount1: 2533
IoCount2: 735
IoCount3: 442
IoCount4: 247
IoCount5: 80
IoCount6: 68
IoCount7: 9
IoCount8: 7
IoCount9: 1
IoCount10: 0
IoCount11: 0
IoCount12: 1
IoCount13: 0
IoCount14: 0
IoCount15: 0
TotalTimeNs0: 1787444100
TotalTimeNs1: 426448000
TotalTimeNs2: 260123100
TotalTimeNs3: 308442200
TotalTimeNs4: 472092800
TotalTimeNs5: 650878800
TotalTimeNs6: 2032031400
TotalTimeNs7: 839490800
TotalTimeNs8: 1281500500
TotalTimeNs9: 482246900
TotalTimeNs10: 0
TotalTimeNs11: 0
TotalTimeNs12: 5739679000
TotalTimeNs13: 0
TotalTimeNs14: 0
TotalTimeNs15: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 171 — File-Level Trim Summary: Volume Id: %1 Volume name: %3 Is boot volume: %4 Period duration (us): %5 Operation count: %6 Reposted operation count: %7...
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | [File-Level Trim Summary] Volume Id. |
VolumeNameLength | — |
VolumeName | [File-Level Trim Summary] Volume name. |
IsBootVolume | [File-Level Trim Summary] Is boot volume. |
PeriodDurationMicrosSec | [File-Level Trim Summary] Period duration (us). |
OperationCount | [File-Level Trim Summary] Operation count. |
RepostedOperationCount | [File-Level Trim Summary] Reposted operation count. |
FailedOperationCount | [File-Level Trim Summary] Failed operation count. |
OperationRangeCount | [File-Level Trim Summary] Operation range count. |
OperationByteCount | [File-Level Trim Summary] Operation byte count. |
OperationLongRangeByteCount | — |
UnalignedRangeCount | [File-Level Trim Summary] Unaligned range count. |
BytesInUnalignedRanges | [File-Level Trim Summary] Bytes in unaligned ranges. |
OperationTrimExtentCount | [File-Level Trim Summary] Operation trim extent count. |
NonBlockAlignedTrimByteCount | [File-Level Trim Summary] Non-blocking aligned trim byte count. |
ReclaimedByteCount | [File-Level Trim Summary] Reclaimed byte count. |
ByteCountLabelsLength | — |
ByteCountLabels | — |
OperationCountBuckets1 | — |
OperationCountBuckets2 | — |
OperationCountBuckets3 | — |
OperationCountBuckets4 | — |
OperationCountBuckets5 | — |
OperationCountBuckets6 | — |
OperationCountBuckets7 | — |
OperationCountBuckets8 | — |
OperationCountBuckets9 | — |
OperationCountBuckets10 | — |
OperationCountBuckets11 | — |
OperationCountBuckets12 | — |
OperationByteCountBuckets1 | — |
OperationByteCountBuckets2 | — |
OperationByteCountBuckets3 | — |
OperationByteCountBuckets4 | — |
OperationByteCountBuckets5 | — |
OperationByteCountBuckets6 | — |
OperationByteCountBuckets7 | — |
OperationByteCountBuckets8 | — |
OperationByteCountBuckets9 | — |
OperationByteCountBuckets10 | — |
OperationByteCountBuckets11 | — |
OperationByteCountBuckets12 | — |
OperationBytesReclaimedBuckets1 | — |
OperationBytesReclaimedBuckets2 | — |
OperationBytesReclaimedBuckets3 | — |
OperationBytesReclaimedBuckets4 | — |
OperationBytesReclaimedBuckets5 | — |
OperationBytesReclaimedBuckets6 | — |
OperationBytesReclaimedBuckets7 | — |
OperationBytesReclaimedBuckets8 | — |
OperationBytesReclaimedBuckets9 | — |
OperationBytesReclaimedBuckets10 | — |
OperationBytesReclaimedBuckets11 | — |
OperationBytesReclaimedBuckets12 | — |
OperationLatencyBuckets1 | — |
OperationLatencyBuckets2 | — |
OperationLatencyBuckets3 | — |
OperationLatencyBuckets4 | — |
OperationLatencyBuckets5 | — |
OperationLatencyBuckets6 | — |
OperationLatencyBuckets7 | — |
OperationLatencyBuckets8 | — |
OperationLatencyBuckets9 | — |
OperationLatencyBuckets10 | — |
OperationLatencyBuckets11 | — |
OperationLatencyBuckets12 | — |
LatencyBucketLabelsLength | — |
LatencyBucketLabelsLabels | — |
OperationCountLatencyBuckets1 | — |
OperationCountLatencyBuckets2 | — |
OperationCountLatencyBuckets3 | — |
OperationCountLatencyBuckets4 | — |
OperationCountLatencyBuckets5 | — |
OperationCountLatencyBuckets6 | — |
OperationCountLatencyBuckets7 | — |
OperationCountLatencyBuckets8 | — |
OperationCountLatencyBuckets9 | — |
OperationCountLatencyBuckets10 | — |
OperationCountLatencyBuckets11 | — |
OperationCountLatencyBuckets12 | — |
OperationCountLatencyBuckets13 | — |
OperationCountLatencyBuckets14 | — |
OperationCountLatencyBuckets15 | — |
OperationFailureStatusCode1 | Top failure status codes and instance counts |
OperationFailureCount1 | — |
OperationFailureStatusCode2 | — |
OperationFailureCount2 | — |
OperationFailureStatusCode3 | — |
OperationFailureCount3 | — |
OperationFailureStatusCode4 | — |
OperationFailureCount4 | — |
OperationFailureStatusCode5 | — |
OperationFailureCount5 | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 171
version: 3
level: 4
task: 0
opcode: 0
keywords: 4611967493406195712
time_created: '2023-11-05T22:47:04.962167+00:00'
event_record_id: 182
correlation: {}
execution:
process_id: 4
thread_id: 52
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: 7597D2A3-4404-4F99-B979-6233378A81BF
VolumeNameLength: 2
VolumeName: 'C:'
IsBootVolume: true
PeriodDurationMicrosSec: 899757629
OperationCount: 2
RepostedOperationCount: 0
FailedOperationCount: 0
OperationRangeCount: 2
OperationByteCount: 0
OperationLongRangeByteCount: 18446744073709551614
UnalignedRangeCount: 0
BytesInUnalignedRanges: 0
OperationTrimExtentCount: 2
NonBlockAlignedTrimByteCount: 0
ReclaimedByteCount: 2030043136
ByteCountLabelsLength: 80
ByteCountLabels: 4 KB, 64 KB, 1 MB, 16 MB, 128 MB, 1 GB, 16 GB, 128 GB, 1 TB, 16
TB, 1 EB, 1+ EB
OperationCountBuckets1: 0
OperationCountBuckets2: 0
OperationCountBuckets3: 0
OperationCountBuckets4: 0
OperationCountBuckets5: 0
OperationCountBuckets6: 0
OperationCountBuckets7: 0
OperationCountBuckets8: 0
OperationCountBuckets9: 0
OperationCountBuckets10: 0
OperationCountBuckets11: 0
OperationCountBuckets12: 2
OperationByteCountBuckets1: 0
OperationByteCountBuckets2: 0
OperationByteCountBuckets3: 0
OperationByteCountBuckets4: 0
OperationByteCountBuckets5: 0
OperationByteCountBuckets6: 0
OperationByteCountBuckets7: 0
OperationByteCountBuckets8: 0
OperationByteCountBuckets9: 0
OperationByteCountBuckets10: 0
OperationByteCountBuckets11: 0
OperationByteCountBuckets12: 0
OperationBytesReclaimedBuckets1: 0
OperationBytesReclaimedBuckets2: 0
OperationBytesReclaimedBuckets3: 0
OperationBytesReclaimedBuckets4: 0
OperationBytesReclaimedBuckets5: 54
OperationBytesReclaimedBuckets6: 0
OperationBytesReclaimedBuckets7: 70
OperationBytesReclaimedBuckets8: 0
OperationBytesReclaimedBuckets9: 0
OperationBytesReclaimedBuckets10: 0
OperationBytesReclaimedBuckets11: 0
OperationBytesReclaimedBuckets12: 0
OperationLatencyBuckets1: 0
OperationLatencyBuckets2: 0
OperationLatencyBuckets3: 0
OperationLatencyBuckets4: 0
OperationLatencyBuckets5: 0
OperationLatencyBuckets6: 0
OperationLatencyBuckets7: 0
OperationLatencyBuckets8: 0
OperationLatencyBuckets9: 0
OperationLatencyBuckets10: 0
OperationLatencyBuckets11: 0
OperationLatencyBuckets12: 248
LatencyBucketLabelsLength: 79
LatencyBucketLabelsLabels: 256us, 1ms, 4ms, 16ms, 64ms, 128ms, 256ms, 2s, 6s, 10s,
20s, 1m, 5m, 15m, 15m+
OperationCountLatencyBuckets1: 2
OperationCountLatencyBuckets2: 0
OperationCountLatencyBuckets3: 0
OperationCountLatencyBuckets4: 0
OperationCountLatencyBuckets5: 0
OperationCountLatencyBuckets6: 0
OperationCountLatencyBuckets7: 0
OperationCountLatencyBuckets8: 0
OperationCountLatencyBuckets9: 0
OperationCountLatencyBuckets10: 0
OperationCountLatencyBuckets11: 0
OperationCountLatencyBuckets12: 0
OperationCountLatencyBuckets13: 0
OperationCountLatencyBuckets14: 0
OperationCountLatencyBuckets15: 0
OperationFailureStatusCode1: '0x0'
OperationFailureCount1: 0
OperationFailureStatusCode2: '0x0'
OperationFailureCount2: 0
OperationFailureStatusCode3: '0x0'
OperationFailureCount3: 0
OperationFailureStatusCode4: '0x0'
OperationFailureCount4: 0
OperationFailureStatusCode5: '0x0'
OperationFailureCount5: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 201 — NtfsLogFileFull VolumeId: %1, Reason: %2.
Message
Fields
| Name | Description |
|---|---|
NtfsLogFileFull_VolumeId | — |
Reason | — |
Vcb | — |
LogFileFullReason | — |
Event ID 202 — PeriodicCheckpointStart VolumeId: %1, Reason: %2, Usage: %3%.
Message
Fields
| Name | Description |
|---|---|
PeriodicCheckpointStart_VolumeId | — |
Reason | — |
Usage | — |
Vcb | — |
LogFileFullReason | — |
LogFileUsePercentage | — |
Event ID 203 — PeriodicCheckpointComplete VolumeId: %1, DirtyMetaDataPages: %2.
Message
Fields
| Name | Description |
|---|---|
PeriodicCheckpointComplete_VolumeId | — |
DirtyMetaDataPages | — |
Vcb | — |
Event ID 204 — CleanCheckpointStart VolumeId: %1, Reason: %2, Usage: %3%.
Message
Fields
| Name | Description |
|---|---|
CleanCheckpointStart_VolumeId | — |
Reason | — |
Usage | — |
Vcb | — |
LogFileFullReason | — |
LogFileUsePercentage | — |
Event ID 205 — CleanCheckpointComplete VolumeId: %1, DirtyMetaDataPages: %2.
Message
Fields
| Name | Description |
|---|---|
CleanCheckpointComplete_VolumeId | — |
DirtyMetaDataPages | — |
Vcb | — |
Event ID 206 — MftRecordRead VolumeId: %1, BaseFileId: %2, FileId: %3, CacheHit: %4.
Message
Fields
| Name | Description |
|---|---|
MftRecordRead_VolumeId | — |
BaseFileId | — |
FileId | — |
CacheHit | — |
Vcb | — |
Event ID 208 — MftRecordRead VolumeId: %1, BaseFileId: %2, FileId: %3.
Message
Fields
| Name | Description |
|---|---|
MftRecordRead_VolumeId | — |
BaseFileId | — |
FileId | — |
Vcb | — |
Event ID 210 — Thinly provisioned volume %1 (%2) were not being mapped between clusters %3 and %4.
Message
Fields
| Name | Description |
|---|---|
VolumeId | — |
DeviceName | — |
Starting LCN | — |
Ending LCN | — |
StartingLCN | — |
EndingLCN | — |
Event ID 211 — Thinly provisioned volume %1 (%2) were not being mapped between clusters %3 and %4.
Message
Fields
| Name | Description |
|---|---|
VolumeId | — |
DeviceName | — |
Starting LCN | — |
Ending LCN | — |
StartingLCN | — |
EndingLCN | — |
Event ID 230 — WorkItem queued, WorkItem: %1, Reason: %2.
Message
Fields
| Name | Description |
|---|---|
WorkItem_queued_WorkItem | WorkItem queued, WorkItem. |
Reason | — |
WorkItem | — |
Event ID 231 — WorkItem queue failed, WorkItem: %1, Reason: %2, Error: %3.
Message
Fields
| Name | Description |
|---|---|
WorkItem_queue_failed_WorkItem | WorkItem queue failed, WorkItem. |
Reason | — |
Error | — |
WorkItem | — |
Event ID 232 — WorkItem started, WorkItem: %1, Reason: %2.
Message
Fields
| Name | Description |
|---|---|
WorkItem_started_WorkItem | WorkItem started, WorkItem. |
Reason | — |
WorkItem | — |
Event ID 233 — WorkItem completed, WorkItem: %1, Reason: %2.
Message
Fields
| Name | Description |
|---|---|
WorkItem_completed_WorkItem | WorkItem completed, WorkItem. |
Reason | — |
WorkItem | — |
Event ID 240 — File metadata optimization started.
Message
Fields
| Name | Description |
|---|---|
Volume_guid | — |
Volume_name | — |
File_reference | — |
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
FileReference | — |
Event ID 241 — File metadata optimization completed.
Message
Fields
| Name | Description |
|---|---|
Volume_guid | — |
Volume_name | — |
File_reference | — |
VolumeGuid | — |
VolumeNameLength | — |
VolumeName | — |
FileReference | — |
Event ID 300 — NTFS volume dismount has started.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | Volume name. |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | Device manufacturer. |
ProductIdLength | — |
ProductId | Device model. |
ProductRevisionLength | — |
ProductRevision | Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Vcb | — |
ProcessId | — |
ProcessName | — |
DismountReason | Reason. |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 300
version: 1
level: 4
task: 8
opcode: 1
keywords: 4611686018427387936
time_created: '2022-03-04T08:48:15.493213+00:00'
event_record_id: 22
correlation: {}
execution:
process_id: 1460
thread_id: 2636
channel: Microsoft-Windows-Ntfs/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: 1E9B06BD-0000-0000-0000-B0C208000000
VolumeIdLength: 48
VolumeId: \\?\Volume{1e9b06bd-0000-0000-0000-b0c208000000}
VolumeLabelLength: 0
VolumeLabel: ''
DeviceNameLength: 23
DeviceName: \Device\HarddiskVolume3
DeviceGuid: A86CEC8E-FB18-5AEC-6F31-C812511391BB
VendorIdLength: 0
VendorId: ''
ProductIdLength: 13
ProductId: VBOX HARDDISK
ProductRevisionLength: 3
ProductRevision: '1.0'
DeviceSerialNumberLength: 19
DeviceSerialNumber: VB8e57de8f-e08973f3
BusType: 11
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
Vcb: '0xffffe706b34661b0'
ProcessId: 1460
ProcessName: vds.exe
DismountReason: Explicit lock
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 301 — NTFS has sent volume dismount event notification and is waiting for the notifications to complete.
Message
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 301
version: 0
level: 4
task: 8
opcode: 8
keywords: 4611686018427387936
time_created: '2022-03-04T08:48:15.535738+00:00'
event_record_id: 24
correlation: {}
execution:
process_id: 1460
thread_id: 2636
channel: Microsoft-Windows-Ntfs/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 302 — The volume dismount event notification on the NTFS volume has completed.
Message
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 302
version: 0
level: 4
task: 8
opcode: 7
keywords: 4611686018427387936
time_created: '2022-03-04T08:48:15.936270+00:00'
event_record_id: 25
correlation: {}
execution:
process_id: 1460
thread_id: 2636
channel: Microsoft-Windows-Ntfs/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 303 — The NTFS volume has successfully dismounted.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | Volume name. |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | Device manufacturer. |
ProductIdLength | — |
ProductId | Device model. |
ProductRevisionLength | — |
ProductRevision | Device revision. |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Vcb | — |
ProcessId | — |
ProcessName | — |
DismountReason | Reason. |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 303
version: 1
level: 4
task: 8
opcode: 2
keywords: 4611686018427387936
time_created: '2022-03-04T08:48:15.535499+00:00'
event_record_id: 23
correlation: {}
execution:
process_id: 1460
thread_id: 2636
channel: Microsoft-Windows-Ntfs/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-18
event_data:
VolumeCorrelationId: 1E9B06BD-0000-0000-0000-B0C208000000
VolumeIdLength: 48
VolumeId: \\?\Volume{1e9b06bd-0000-0000-0000-b0c208000000}
VolumeLabelLength: 0
VolumeLabel: ''
DeviceNameLength: 23
DeviceName: \Device\HarddiskVolume3
DeviceGuid: A86CEC8E-FB18-5AEC-6F31-C812511391BB
VendorIdLength: 0
VendorId: ''
ProductIdLength: 13
ProductId: VBOX HARDDISK
ProductRevisionLength: 3
ProductRevision: '1.0'
DeviceSerialNumberLength: 19
DeviceSerialNumber: VB8e57de8f-e08973f3
BusType: 11
AdapterSerialNumberLength: 0
AdapterSerialNumber: ''
Vcb: '0xffffe706b34661b0'
ProcessId: 1460
ProcessName: vds.exe
DismountReason: Explicit lock
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 304 — The NTFS volume dismount failed.
Message
Fields
| Name | Description |
|---|---|
Error | Volume correlation Id. |
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | — |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
NativeNVMe | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
Vcb | — |
Event ID 305 — NTFS failed to mount the volume.
Message
Fields
| Name | Description |
|---|---|
Error | Volume correlation Id. |
Volume_GUID | — |
Volume_Name | — |
VolumeCorrelationId | — |
VolumeIdLength | — |
VolumeId | — |
VolumeLabelLength | — |
VolumeLabel | — |
DeviceNameLength | — |
DeviceName | — |
DeviceGuid | — |
VendorIdLength | — |
VendorId | — |
ProductIdLength | — |
ProductId | — |
ProductRevisionLength | — |
ProductRevision | — |
DeviceSerialNumberLength | — |
DeviceSerialNumber | — |
BusType | — |
DeviceNumber | — |
IsBootVolume | — |
NativeNVMe | — |
AdapterSerialNumberLength | — |
AdapterSerialNumber | — |
RestartApplied | — |
MountStageSourceTag | — |
Event ID 401 — Efs offloading initiated.
Message
Fields
| Name | Description |
|---|---|
Volume_serial | — |
File_reference | — |
File_name | — |
VolumeSerialNumber | — |
FileReference | — |
FileNameLength | — |
FileName | — |
Event ID 402 — Efs offloading read regular file.
Message
Fields
| Name | Description |
|---|---|
Volume_serial | — |
File_reference | — |
File_name | — |
VolumeSerialNumber | — |
FileReference | — |
FileNameLength | — |
FileName | — |
Event ID 403 — Efs offloading write regular file.
Message
Fields
| Name | Description |
|---|---|
Volume_serial | — |
File_reference | — |
File_name | — |
VolumeSerialNumber | — |
FileReference | — |
FileNameLength | — |
FileName | — |
Event ID 404 — Efs legacy initiated.
Message
Fields
| Name | Description |
|---|---|
Volume_serial | — |
File_reference | — |
File_name | — |
VolumeSerialNumber | — |
FileReference | — |
FileNameLength | — |
FileName | — |
Event ID 405 — Efs legacy read regular file.
Message
Fields
| Name | Description |
|---|---|
Volume_serial | — |
File_reference | — |
File_name | — |
VolumeSerialNumber | — |
FileReference | — |
FileNameLength | — |
FileName | — |
Event ID 406 — Efs legacy write regular file.
Message
Fields
| Name | Description |
|---|---|
Volume_serial | — |
File_reference | — |
File_name | — |
VolumeSerialNumber | — |
FileReference | — |
FileNameLength | — |
FileName | — |
Event ID 500 — A process has created a USN journal on a volume.
Message
Fields
| Name | Description |
|---|---|
ProcessName | Process. |
VolumeCorrelationId | Volume Id. |
VolumeNameLength | — |
VolumeName | — |
JournalId | — |
MaximumSize | — |
AllocationDelta | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 500
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018429485056
time_created: '2023-10-26T04:16:37.820075+00:00'
event_record_id: 7
correlation: {}
execution:
process_id: 428
thread_id: 432
channel: Microsoft-Windows-Ntfs/Operational
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
event_data:
ProcessName: System
VolumeCorrelationId: 7597D2A3-4404-4F99-B979-6233378A81BF
VolumeNameLength: 2
VolumeName: 'C:'
JournalId: '0x1da07c336abde45'
MaximumSize: '0x2000000'
AllocationDelta: '0x800000'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 501 — A process has deleted a USN journal on a volume.
Message
Fields
| Name | Description |
|---|---|
ProcessName | Process. |
VolumeCorrelationId | Volume Id. |
VolumeNameLength | — |
VolumeName | — |
JournalId | — |
CurrentUsn | — |
Example Event
system:
provider: Microsoft-Windows-Ntfs
guid: 3FF37A1C-A68D-4D6E-8C9B-F79E8B16C482
event_source_name: ''
event_id: 501
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018429485056
time_created: '2023-11-06T06:25:51.720407+00:00'
event_record_id: 151
correlation: {}
execution:
process_id: 5004
thread_id: 5064
channel: Microsoft-Windows-Ntfs/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
ProcessName: SearchIndexer.
VolumeCorrelationId: 7597D2A3-4404-4F99-B979-6233378A81BF
VolumeNameLength: 2
VolumeName: 'C:'
JournalId: '0x1da07c336abde45'
CurrentUsn: '0x0'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 502 — File has been opened by an isolated reader.
Message
Fields
| Name | Description |
|---|---|
VolumeCorrelationId | — |
VolumeNameLength | — |
VolumeName | — |
FileReference | — |
FileNameLength | — |
FileName | — |
KtmTransaction | — |