Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005

701 events across 1 channel

Event IDTitleChannel
10NtfsLookupRealAllocation: Vcn A10_Vcn!Operational
11NtfsAllocateAttribute MaxAlloc for Mft's AttrList IC:A10_IrpContext, …Operational
12FileObject: A10_FileObject, Scb: A11_Scb, StaringVcn: A12_StartingVcn!Operational
13NtfsAddAllocation IC:A10_IrpContext, FileObject:A11_FileObject, Scb:A12_Scb, …Operational
14Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!Operational
15Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!Operational
16NtfsGetLastVcnForNewMappingPairSize IC:A10_IrpContext, Using …Operational
17Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber( _Fcb->FileReference )!Operational
18Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber( _Fcb->FileReference )!Operational
19NtfsCreateNonresidentWithValue Create Mft's NonResident Attribute List …Operational
20NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
21NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
22NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
23NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
24NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
25NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
26NtfsRestartRemoveAttribute FileRef:0xA10_FileRecord->SegmentNumberHighPart!Operational
27NtfsRestartChangeValue FileRef:0xA10_FileRecord->SegmentNumberHighPart!Operational
28AddToAttributeList(A10_Fcb->Vcb,A11_IrpContext): FRef …Operational
29DeleteFromAttributeList(A10_Fcb->Vcb,A11_IrpContext): FRef …Operational
30MakeRoomForAttribute Moving Mft's attribute IC:A10_IrpContext, Moving Attrib …Operational
31MoveAttributeToOwnRecord Moving Mft's $BITMAP IC:A10_IrpContext, …Operational
32MoveAttributeToOwnRecord IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, …Operational
33NtfsRestartZeroEndOfFileRecord FileRef:0xA10_FileRecord->SegmentNumberHighPart!Operational
34MergeFRS2(%1,%2): Scb %3, FileRef %4!Operational
35MergeFRS2(%1,%2): Scb %3, FileRef %4!Operational
36MergeFRS2(%1,%2): Scb %3, FileRef %4!Operational
37MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
38MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
39MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
40MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
41MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
42MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
43MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
44MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
45MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
46MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
47MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef …Operational
48RedoAttribute(%1,%2): Scb %3, FileRef %4!Operational
49RedoAttribute(%1,%2): Scb %3, FileRef %4!Operational
50NtfsConsolidateAllFileRecords: Invalid Vcb.Operational
51NtfsConsolidateAllFileRecords: Volume is locked.Operational
52NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
53NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
54NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
55NtfsConsolidateAllFileRecords(%1,%2): Fcb %3, FileRef %4!Operational
56NtfsConsolidateAllFileRecords(%1,%2): Fcb %3, FileRef %4!Operational
57NtfsConsolidateAllFileRecords(%1,%2): Fcb %3, FileRef %4!Operational
58NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
59NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
60NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): FileRef …Operational
61NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
62NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
63NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
64NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef …Operational
65NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): DeltaTime …Operational
66UpdateLCS: Vcb A10_Fcb->Vcb, IC A11_IrpContext, FRef …Operational
67NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: …Operational
68NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: …Operational
69NtfsAllocateClustersPriv: Incremented TotalAllocated by 0xA10_FoundClusterCount!Operational
70NtfsAllocateClustersPriv: Skipped incrementing TotalAllocated by …Operational
71NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: …Operational
72NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: …Operational
73NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: …Operational
74NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR …Operational
75NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: …Operational
76NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR …Operational
77NtfsDeallocateClusters: Vcb A10_Vcb - raising logfile full.Operational
78NtfsDeallocateClusters: Vcb A10_Vcb - adding clusters to DeallocatedClusters: …Operational
79NtfsDeallocateClusters: Decremented TotalAllocated by 0xA10_ClusterCount!Operational
80NtfsDeallocateClusters: Skipped decrementing TotalAllocated by …Operational
81NtfsDeallocateClusters: Vcb A10_Vcb - Undoing some changes to …Operational
82NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: …Operational
83NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: …Operational
84NtfsModifyBitsInBitmap IC: A10_IrpContext, Vcb: A11_Vcb, FirstBit: …Operational
85NtfsModifyBitsInBitmap IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: …Operational
86NtfsAllocateBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: …Operational
87NtfsAllocateBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: …Operational
88NtfsRestartSetBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, BitMapOffset: …Operational
89NtfsFreeBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: …Operational
90NtfsFreeBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: …Operational
91NtfsRestartClearBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, …Operational
92NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: …Operational
93NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Bitmap: A11_Bitmap, StartLcn: …Operational
94NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Result: A11_Results.Operational
95System files not marked as in use in the MFT bitmap.Operational
96Length: 0 --> BinIndex : 0 - Unexpected length.Operational
97Length: A10_Length!Operational
98Length: A10_Length!Operational
99BinIndex: A10_BinIndex!Operational
100BinIndex: A10_BinIndex!Operational
101BinGroupShift: A10_NtfsCachedRunBinGroupShift!Operational
102BinIndex: A10_BinIndex!Operational
103Searched committed allocations but didnt find enough free space.Operational
104NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): first bit …Operational
105NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no leading …Operational
106NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): leading …Operational
107NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no trailing …Operational
108NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): trailing …Operational
109NtfsValidateTotalClustersCommitted(A10_Vcb,A11_PsGetCurrentThread()): TCC …Operational
110Illegal MDL Complete for major code A10_IrpContext->MajorFunction.Operational
111Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!Operational
112RunEntry ==> A10_RunIndex!Operational
113Offset is beyond this extent skipping the extent.Operational
114Shrinking LengthInExtent.Operational
115Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddr.QuadPart!Operational
116Exiting: ExtentsDescriptorIndex: A10_*ExtentsDescriptorIndex …Operational
117Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingOffset!Operational
118Dsm Ranges[A10_DataSetRangeIndex]: StartingOffset: …Operational
119RemainingClusterCount: 0xA10_RemainingClusterCount!Operational
120Dsm: TotalNumberOfRanges: A10_DsmByteAddressRanges->TotalNumberOfRanges, …Operational
121DsmOut Ranges[A10_Index]: StartingAddress: …Operational
122Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddr.QuadPart!Operational
123Updating ExtentsDescriptor Index and StartOffset from Locals: …Operational
124Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!Operational
125Updating ExtentsDescriptor Index and StartOffset from Locals: …Operational
126IrpContext: A10_IrpContext; Scb: A11_Scb; StartOffset: 0xA12_StartOffset!Operational
127Return.Operational
128Unexpected open type received: A10_TypeOfOpen.Operational
129Raising STATUS_SUCCESS from NtfsCommonCleanup: A10_Status.Operational
130Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.Operational
131Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.Operational
132Irp: %1, IC: %2, Vcb: %3, FileObject: %4, RelatedFileObject: %5, FileIdBuffer: …Operational
133Irp: %1, IC: %2, Vcb: %3, FileObject: %4, RelatedFileObject: %5, Path: %6, …Operational
134NtfsCommonCreate: Volume is locked or we have performed a dismount.Operational
135NtfsCommonVolumeOpen: Invalid create disposition for volume open.Operational
136NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.Operational
137NtfsCommonVolumeOpen: Thread: %1, Vcb: %2, VolumeName: %3, VolumeLabel: %4, …Operational
138NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.Operational
139NtfsCommonVolumeOpen: Conlicting file objects.Operational
140NtfsHandlePagingFile: Paging file already open, paging files can only be opened …Operational
141NtfsHandlePagingFile: Cannot open system file as paging file.Operational
142NtfsHandlePagingFile: Persisted paging file already exists.Operational
143NtfsOpenFcbById: Invalid system file access.Operational
144NtfsOpenExistingPrefixFcb: Can not directly open txf directory.Operational
145NtfsOpenExistingPrefixFcb: Invalid system file access.Operational
146NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system …Operational
147NtfsOpenFile: Invalid system file access.Operational
148NtfsOpenFile: Deny open when txf rm is active.Operational
149NtfsCreateNewFile: Deny creation in system directory (except root).Operational
150NtfsCreateNewFile: Unable to create Ea for the file.Operational
151NtfsCreateNewFile: Unable to create in the $txf directory.Operational
152NtfsOpenSubdirectory: Denying access to $Txf file when the RM is active.Operational
153NtfsOpenAttributeInExistingFile: Denying access due to caller being Ea blind.Operational
154NtfsOpenAttributeInExistingFile: Fail to find $INDEX_ROOT attribute.Operational
155NtfsOpenAttributeInExistingFile: Denying access for volume root directory.Operational
156NtfsCreateNewFile: Not allowed to create streams on system files.Operational
157NtfsOverwriteAttr: Cannot overwrite hidden or system attribute for a non-paging …Operational
158NtfsOverwriteAttr: Denying access due to user being Ea blind.Operational
159NtfsOverwriteAttr: Deny access due to encryption happening on the stream.Operational
160NtfsCheckValidAttributeAccess: Supersede or overwrite is not allowed on this …Operational
161NtfsCheckValidAttributeAccess: Only read attributes access is supported on this …Operational
162NtfsCheckValidAttributeAccess: Deny access for protected system attributes.Operational
163NtfsOpenAttributeCheck: File already has user writable references.Operational
164NtfsOpenAttributeCheck: Deny access for online encryption backup data stream.Operational
165NtfsOpenAttributeCheck: File was granted write access but has image section.Operational
166NtfsOpenAttribute: Denying write access on disallowed writes.Operational
167NtfsOpenAttribute: File already has user writable references.Operational
168NtfsOpenAttribute: Open for exclusive read access is not allowed.Operational
169NtfsOpenAttribute: File already has user writable references.Operational
170NtfsOpenAttribute: Open for exclusive read access is not allowed.Operational
171NtfsCheckExistingFile: Desired access conflicts with read-only state.Operational
172NtfsOpenExistingEncryptedStream: No encryption driver found.Operational
173NtfsOpenExistingEncryptedStream: Opening for read/write access not allowed on …Operational
174NtfsEncryptionCreateCallback: Encrytion engine fail to encrypt all streams for …Operational
175NtfsFindStartingNode: Opening not allowed for txf name when RM is active.Operational
176NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.Operational
177NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.Operational
178NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.Operational
179NtfsReCheckShareAccess: Does not meet allow open requirement.Operational
180%1:%2 Status: %3 ProcessName: %4.Operational
181%1:%2 Status: %3 ProcessName: %4.Operational
182%1:%2 Status: %3 ProcessName: %4.Operational
183%1:%2 Status: %3 ProcessName: %4.Operational
184NtfsSendUnusedClustersHint: Vcb A10_Vcb - Will tell storage we are freeing at …Operational
185NtfsSendUnusedClustersHint: Vcb A10_Vcb - Flush requested.Operational
186NtfsSendUnusedClustersHint: Vcb A10_Vcb - Created new MarkUnusedContext …Operational
187NtfsSendUnusedClustersHint: Vcb A10_Vcb - Successfully added clusters starting …Operational
188NtfsSendUnusedClustersHint: Vcb A10_Vcb - MCB …Operational
189NtfsSendUnusedClustersHint: Vcb A10_Vcb - Queuing request to IC pre-trim list, …Operational
190NtfsSendUnusedClustersHint: Vcb A10_Vcb - Failed to allocate/initial …Operational
191NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt …Operational
192NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt …Operational
193NtfsMarkUnusedContextPostTrimProcessing: Entering.Operational
194NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext …Operational
195NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext …Operational
196NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - Releasing bitmap.Operational
197NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - CloseCount …Operational
198NtfsMarkUnusedContextPostTrimProcessing: Leaving.Operational
199NtfsAsyncSendUnusedClustersHintCompletionRoutine: Irp A10_Irp.Operational
200NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb, IC A11_IrpContext - …Operational
201NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Kicked off …Operational
202NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Leaving.Operational
203NtfsMarkUnusedContextPreTrimWorkItemProcessing: Entering Vcb A10_Vcb.Operational
204NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Small MUC …Operational
205NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Failed to allocate …Operational
206NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage …Operational
207NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC …Operational
208NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC …Operational
209NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC …Operational
210NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Add MUC …Operational
211NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Free small MUC …Operational
212NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage …Operational
213NtfsMarkUnusedContextPreTrimWorkItemProcessing: Leaving.Operational
214NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - There are waiters for DC …Operational
215NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Waking up waiter for DC …Operational
216NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Done waking up DC …Operational
217NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb, All A11_All - Entering.Operational
218NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting to drain.Operational
219NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting for partial drain.Operational
220NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.Operational
221NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Entering.Operational
222NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Inserted …Operational
223NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.Operational
224NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Vcb A10_IrpContext->Vcb - …Operational
225NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds …Operational
226NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds …Operational
227NtfsCheckForTrimThrottling: Vcb A10_Vcb - hitting trim threshold …Operational
228NtfsUpdateSmartTrimState: Vcb A10_Vcb - Entering.Operational
229NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed.Operational
230NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed; …Operational
231NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - Skipping …Operational
232NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - MCB run …Operational
233NtfsUpdateSmartTrimState: Vcb A10_Vcb - MUC A11_MarkUnusedContext, DSR count …Operational
234NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DSR range …Operational
235NtfsUpdateSmartTrimState: Vcb A10_Vcb - MCB lcn A11_StartingLcn!Operational
236NtfsUpdateSmartTrimState: Vcb A10_Vcb - Smart trim state on exit; …Operational
237NtfsUpdateSmartTrimState: Vcb A10_Vcb - Range A11_SlabRangeIndex: FirstTPMapBit …Operational
238NtfsUpdateSmartTrimState: Vcb A10_Vcb - Leaving.Operational
239NtfsEvalSmartTrimState: Vcb A10_Vcb - Entering.Operational
240NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed.Operational
241NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed; AcquiredBitmap …Operational
242NtfsEvalSmartTrimState: Vcb A10_Vcb - Checking slab 0xA11_TpMapBit for …Operational
243NtfsEvalSmartTrimState: Vcb A10_Vcb - Slab 0xA11_TpMapBit has allocations, will …Operational
244NtfsEvalSmartTrimState: Vcb A10_Vcb - Free slab found - TP map bit …Operational
245NtfsEvalSmartTrimState: Vcb A10_Vcb - Leaving.Operational
246NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume.Operational
247NtfsVolumeDasdIo: Data section blocking flush.Operational
248Could not find paging file run.Operational
249Could not find paging file MCB entry.Operational
250Could not find paging file run.Operational
251Writing to $Bitmap.Operational
252NTFS: Posting hotfix on file object: A10_FileObject.Operational
253NTFS: Freeing Bad Vcn: A10_((ULONG)BadVcn)!Operational
254NTFS: Retiring Bad Lcn: A10_((ULONG)BadLcn)!Operational
255NTFS: Reallocating Bad Vcn.Operational
256NTFS: Bad Cluster replaced.Operational
257IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!Operational
258Compression buffers are already big enough.Operational
259A10_Status.Operational
260IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!Operational
261Compression buffers are already big enough.Operational
262A10_Status.Operational
263NtfsDefragFileInternal: Defrag is denied.Operational
264NtfsDefragFileInternal: Vcb A10_Vcb - Calling FRD.Operational
265NtfsDefragFileInternal: Vcb A10_Vcb - Done calling FRD.Operational
266NtfsDefragFileInternal: Defrag is denied.Operational
267NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef …Operational
268NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef …Operational
269NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef …Operational
270NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef …Operational
271NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef …Operational
272NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef …Operational
273NtfsDefragFile: Defrag is denied without manage volume access.Operational
274NtfsEncryptDecryptOnline: Defrag is denied.Operational
275NtfsEncryptDecryptOnline: Vcb A10_Vcb - Calling FRD.Operational
276NtfsEncryptDecryptOnline: Vcb A10_Vcb - Done calling FRD.Operational
277NtfsEncryptDecryptOnline: Defrag is denied.Operational
278SCB: A10_Scb, VDL=0xA11_Scb->Header.ValidDataLength.QuadPart!Operational
279StartOff=0xA10_QueryDaxExtents->FileOffset!Operational
280NumberOfValidRuns: 0.Operational
281RemainingClusterCount: 0xA10_RemainingClusterCount!Operational
282STATUS_BUFFER_TOO_SMALL from FsLib.Operational
283Made an educated guess for remaining runs.Operational
284Made a wild guess for remaining runs.Operational
285NumberOfValidRuns: 0xA10_ExtentsDescriptor->NumberOfValidRuns!Operational
286BasePage: 0xA10_ExtentsDescriptor->Run[Index].BasePage!Operational
287About to zero range - ZeroStart: 0xA10_ZeroStart!Operational
288Zeroed range - ZeroStart: 0xA10_ZeroStart!Operational
289NtfsCommonQueryInformation: File information query not allowed as file was …Operational
290NtfsQueryCaseSensitiveInfo: Case sensitive info query not allowed without read …Operational
291NtfsQueryNameInfo: Name info query not allowed as file was opened without …Operational
292NtfsQueryLinksInfo: Link info query not allowed as file was opened without …Operational
293NtfsSetCaseSensitiveInfo: Cannot mark root directory of a volume case-sensitive.Operational
294NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file.Operational
295NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with …Operational
296NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with …Operational
297NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened …Operational
298NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with …Operational
299NtfsSetRenameInfo: Can not rename a file marked for deletion.Operational
300NtfsSetRenameInfo: Can not rename a txf directory.Operational
301NtfsSetRenameInfo: Can not rename into a system directory.Operational
302NtfsSetRenameInfo: Can not rename a file that is part of a TxF transaction.Operational
303NtfsSetRenameInfo: The file should not have in-memory directory descendents.Operational
304NtfsSetRenameInfo: Child Scb mismatch.Operational
305NtfsSetLinkInfo: Set link info is not allowed on txf directory.Operational
306NtfsSetLinkInfo: Set link info is not allowed on a file in a TxF transaction.Operational
307NtfsSetLinkInfo: Set link info failed due to caller not having …Operational
308NtfsSetLinkInfo: Creating a link in system directory is not allowed.Operational
309NtfsSetLinkInfo: Creating a link in $txf is not allowed if the RM is running.Operational
310NtfsSetShortNameInfo: Can not set a short name on a deleted file.Operational
311NtfsSetShortNameInfo: Can not set a short name on a file under the $TxF …Operational
312NtfsCheckScbForLinkRemoval: Existing handles are not allowed if Txf transaction …Operational
313NtfsCheckScbForLinkRemoval: Not all open handles for the stream are by-id opens.Operational
314NtfsStreamRename: Deny access due to encryption happening on source stream.Operational
315NtfsProcessTreeForRename: Deny access due to number of batch oplocks has grown.Operational
316NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread(), Vcb: A11_Vcb, …Operational
317NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread(), Scb: A11_Scb.Operational
318NtfsFlushVolume: Thread: A10_PsGetCurrentThread(), Vcb: A11_Vcb, LocalFlags: …Operational
319NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on BitmapScb Scb: …Operational
320NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on MftScb Scb: …Operational
321NtfsFlushCompletionRoutine: Vcb A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb - …Operational
322NtfsFlushCompletionRoutine: Vcb A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb - …Operational
323NtfsDiskFlushContextWorkItemProcessing: Process work item.Operational
324NtfsDiskFlushContextWorkItemProcessing: Nothing to work on.Operational
325Irp: A10_Irp, IC: A11_IrpContext, Vcb: A12_IrpContext->Vcb, MinorCode: …Operational
326NtfsLockVolumeInternal: Cannot lock the volume.Operational
327NtfsLockVolumeInternal: Volume is already locked.Operational
328NtfsLockVolumeInternal: Failed to flush system files on the volume.Operational
329NtfsLockVolumeInternal: Failed to flush system files on the volume.Operational
330NtfsLockVolumeInternal: Outstanding user files open after flush and retry.Operational
331NtfsLockVolume: Cannot lock volume due to caller does not have manage volume …Operational
332NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume.Operational
333A10___FUNCTION__: Setting RM at 0xA11_(PVOID)Vcb->TxfVcb.DefaultRm …Operational
334NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume …Operational
335NtfsDismountVolume: IC: %1, Vcb: %2, Label: %3, DeviceName: %4.Operational
336NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open …Operational
337NtfsDismountVolume: Cannot dismount volume due to volume being locked.Operational
338NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open …Operational
339NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage …Operational
340NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage …Operational
341NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage …Operational
342NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having …Operational
343NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to …Operational
344NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to …Operational
345NtfsCreateUsnJournal: Cannot create Usn journal due to caller not having manage …Operational
346NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not …Operational
347NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage …Operational
348NtfsFindFilesOwnedBySid: Caller not having manage volume privilege, backup …Operational
349NtfsFindFilesOwnedBySid: Caller not having manage volume privilege or backup …Operational
350NtfsSetSparse: Caller does not have appropriate write access to the stream.Operational
351NtfsSetSparse: Cannot desparse encrypted file without write data access.Operational
352NtfsZeroRange: User mode caller not allowed.Operational
353IC: A10_IrpContext, Scb: A11_Scb, FileObject: A12_IrpSp->FileObject.Operational
354IC: A10_IrpContext, EncryptionOperation: 0xA11_EncryptionOperation!Operational
355NtfsReadRawEncrypted: Caller does not have backup access or read data access.Operational
356NtfsWriteRawEncrypted: Caller does not have write data access or restore access.Operational
357NtfsWriteRawEncrypted: Caller not having manage volume privilege.Operational
358NtfsLookupStreamFromCluster: Caller not having manage volume privilege.Operational
359NtfsChangeVolumeSize: Caller not having manage volume privilege.Operational
360NtfsChangeVolumeSize (A10_Vcb): Calling NtfsFreeRecentlyDeallocated.Operational
361NtfsChangeVolumeSize (A10_Vcb): Done calling NtfsFreeRecentlyDeallocated.Operational
362NtfsMarkHandle: Caller does not have a valid volume handle or manage volume …Operational
363NtfsMarkHandle: Caller not having manage volume privilege.Operational
364NtfsMarkHandle: Cannot deny defrag.Operational
365NtfsMarkHandle: Cannot deny Frs consolidation.Operational
366NtfsMarkHandle: Cannot filter metadata.Operational
367NtfsMarkHandle: Mark handle is not allowed on system files.Operational
368NtfsMarkHandle: File already has user writable references.Operational
369NtfsMarkHandle: File was granted write access previously but no oplocks were …Operational
370NtfsPrefetchFile: Caller not having manage volume privilege.Operational
371NtfsSetZeroOnDeallocate: Only allowed on regular user files opened for write.Operational
372NtfsSetShortNameBehavior: Caller not having manage volume privilege.Operational
373Setting VCB_EXT_CHAR_STATE_ALLOW_EXT_CHAR for volume 0xA10_(PVOID)Vcb to …Operational
374NtfsQueryPagefileEncryption: Caller not having manage volume privilege.Operational
375NtfsQueryPagefileEncryption: Caller not having manage volume privilege.Operational
376NtfsResetVolsnapBehaviorForVolume: Volsnap hints are disabled by registry.Operational
377NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.Operational
378Resetting Volsnap behavior for VCB = 0xA10_Vcb.Operational
379NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.Operational
380NtfsCorruptionHandling: Caller not having manage volume privilege.Operational
381NtfsGlobalCorruptionHandling: Caller does not have manage volume privilege.Operational
382Scrub resume from SystemScbIndex: A10_ScrubResumeContext.SystemScbIndex Vcn: …Operational
383Scb:A10_Scb Scrub resume from Vcn: A11_ScrubResumeContext.ResumeVcn!Operational
384Scrub SystemScbIndex: A10_ScrubResumeContext.SystemScbIndex.Operational
385NtfsScrubData: Caller not having manage volume privilege.Operational
386Scrub not supported for Txf file, Scb: A10_Scb, TxfScb: A11_Scb->TxfScb.Operational
387Scrub SCRUB_DATA_INPUT_FLAG_SKIP_NON_INTEGRITY_DATA is request.Operational
388Scb:A10_Scb ScrubInternal OperationStatus: A11_ScrubContext.OperationStatus …Operational
389Scb:A10_Scb ScrubInternal Status: A11_Status Repaired: …Operational
390InternalFileReference: A10_InternalFileReference.Operational
391InternalFileReference:A10_InternalFileReference.Operational
392Scb:A10_Scb Incomplete IoCount:A11_ScrubIoCount Cancel:A12_Irp->Cancel …Operational
393Scb:%1 Scrub skipping resident attribute (d) (%2).Operational
394Scb:%1 Scrub skipping resident attribute (%2).Operational
395Scb:A10_Scb Scrub StartingVcn.Operational
396Scb:A10_Scb Scrub starting vcn is beyond VDL.Operational
397Scb:A10_Scb Scrub no more Mcb entries from StartingVcn:A11_StartingVcn!Operational
398Scb:A10_Scb Scrub skipping UNUSED_LCN Vcn: A11_StartingVcn!Operational
399Scb:A10_Scb StartingVcn:A11_StartingVcn!Operational
400Scb:A10_Scb ScrubDsmRange [A11_DsmRange.StartingOffset!Operational
401Scrub found problems Scb: A10_Scb Vcn A11_StartingVcn!Operational
402Scb:A10_Scb DsmAction_Scrub call failed, Status: A11_Status.Operational
403Scb:A10_Scb DsmAction_Scrub operation failed, Status: A11_Status.Operational
404FSCTL_REPAIR_COPIES not supported for Txf file, Scb: A10_Scb, TxfScb: …Operational
405Scb:%1 FSCTL_REPAIR_COPIES skipping resident attribute (d) (%2).Operational
406Scb:%1 FSCTL_REPAIR_COPIES skipping resident attribute (%2).Operational
407FSCTL_REPAIR_COPIES interrupted by thread termination.Operational
408FSCTL_REPAIR_COPIES canceled.Operational
409Scb:A10_Scb FSCTL_REPAIR_COPIES no more Mcb entries from …Operational
410Scb:A10_Scb FSCTL_REPAIR_COPIES No more Mcb entries (unallocated) from …Operational
411Scb:A10_Scb FSCTL_REPAIR_COPIES skipping UNUSED_LCN Vcn: A11_StartingVcn!Operational
412Scb:A10_Scb RepairDsmRange [A11_RepairDataSetRange->StartingOffset!Operational
413Scb:A10_Scb DsmAction_Repair call failed, Status: A11_Status.Operational
414Scb:A10_Scb DsmAction_Repair operation failed, Status: A11_IrpStatus.Operational
415Scb:A10_Scb DsmAction_Repair completed, IrpStatus: …Operational
416NtfsQueryCachedRuns: Caller not having manage volume privilege.Operational
417NtfsQueryStorageClasses: Caller not having manage volume privilege.Operational
418NtfsQueryRegionInfo: Caller not having manage volume privilege.Operational
419NtfsUnloadFile: Caller not having manage volume privilege.Operational
420NtfsCheckForSection: File already has image section.Operational
421NtfsShuffleFile: User mode caller is not allowed.Operational
422NtfsShuffleFile: Denying access due to volume is locked.Operational
423NtfsShuffleFile: Defrag is denied.Operational
424NtfsShuffleFile: Denying access due to conflicting with read-only state.Operational
425NtfsRearrangeFile: User mode caller is not allowed.Operational
426NtfsRearrangeFile: Denying access due to volume is locked.Operational
427NtfsRearrangeFile: Defrag is denied.Operational
428NtfsShuffleFile: Denying access due to conflicting with read-only state.Operational
429NtfsSparseOverAllocate: Caller does not have appropriate write access.Operational
430NtfsInitiateFileMetadataOptimization: Only allowed on regular user …Operational
431NtfsQueryFileMetadataOptimization: Only allowed on regular user …Operational
432NtfsCleanVolumeMetadata: Caller not having manage volume privilege.Operational
433NtfsEnumOnMountToDeleteWorker(%1,%2): Open status=0x%3, path="%4".Operational
434NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread()): Enumerate …Operational
435NtfsEnumMountWorker(%1,%2): Open status=0x%3, file="%4".Operational
436NtfsEnumMountWorker(A10_Vcb,A11_PsGetCurrentThread()): Close …Operational
437NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread()): Close dir …Operational
438NtfsCleanVolumeMetadata: Caller not having manage volume privilege.Operational
439SCB: A10_Scb, StartOffset: 0xA11_StartOffset!Operational
440FsLibGetBadAddressRanges returned Status: A10_Status, NumBadRanges: …Operational
441FsInputRangeIndex: A10_FsInputRangeIndex, FileOffset: …Operational
442Scb: A10_Scb, Status: A11_Status, AbnormalTermination: …Operational
443Scb: A10_Scb, Status: A11_Status.Operational
444NtfsEncryptionKeyCtl: Caller does not have SE_TCB_PRIVILEGE.Operational
445Logic error of posting close to work queue.Operational
446NtfsFindPrefixHashEntry: {Hash table: %1} {ParentScb: %2, '%3'} {RemainingName: …Operational
447NtfsFindPrefixHashEntry: {Lcb: NULL}.Operational
448NtfsFindPrefixHashEntry: {Lcb: %1, '%2'}.Operational
449NtfsFindPrefixHashEntry: {Lcb not found}.Operational
450NtfsInsertHashEntry: {Hash table: %1} {HashValue: %2!Operational
451NtfsRemoveHashEntry: {Hash table: %1} {HashValue: %2!Operational
452Vcb A10_Vcb.Operational
453Vcb A10_Vcb.Operational
454Vcb A10_Vcb.Operational
455Vcb A10_Vcb.Operational
456Vcb A10_Vcb.Operational
457Vcb A10_Vcb.Operational
458Vcb A10_Vcb.Operational
459Vcb A10_Vcb.Operational
460Vcb A10_Vcb.Operational
461Vcb A10_Vcb.Operational
462Vcb A10_Vcb.Operational
463Vcb A10_Vcb.Operational
464Vcb A10_Vcb.Operational
465NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: …Operational
466NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: …Operational
467NtfsCommitCurrentTransaction …Operational
468NtfsCommitCurrentTransaction …Operational
469NtfsCommitCurrentTransaction …Operational
470NtfsCommitCurrentTransaction …Operational
471NtfsCommitCurrentTransaction …Operational
472NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: …Operational
473NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: …Operational
474NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Entering - ActiveLsn: …Operational
475NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.Operational
476NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.Operational
477NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found frozen deallocated clusters …Operational
478NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.Operational
479NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.Operational
480NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found a deallocated clusters …Operational
481Vcb: A10_Vcb, Processing range.Operational
482Looking for dangling MDLs.Operational
483FsLibGroupSubExtentsByDanglingMdl failed: A10_Status.Operational
484FsLibAddBaseMcbEntryEx failed: A10_Status.Operational
485NtfsAddToMatchingDeallocatedClusters( ExtentsWithoutDanglingMdl ) failed: …Operational
486NtfsAddToMatchingDeallocatedClusters( ExtentsWithDanglingMdl ) failed: …Operational
487No sub extents has dangling MDL.Operational
488NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Telling volsnap freeing at …Operational
489NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Volsnap responsed with freeing at …Operational
490NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Got error 0xA11_Status from below.Operational
491NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Deleting MarkUnusedContext …Operational
492NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Leaving.Operational
493NtfsRemoveNtfsMcbEntry Scb: A10_Mcb->Scb, Mcb: A11_Mcb, Vcn: 0xA12_StartingVcn!Operational
494NtfsRemoveNtfsMcbEntry Mcb: A10_Mcb Completed.Operational
495NtfsAddNtfsMcbEntry Scb: A10_Mcb->Scb, Mcb: A11_Mcb, Vcn: 0xA12_Vcn!Operational
496NtfsAddNtfsMcbEntry Mcb: A10_Mcb, Result: A11_Result.Operational
497NtfsUnloadNtfsMcbRange Scb: A10_Mcb->Scb, Mcb: A11_Mcb, StartVcn: …Operational
498NtfsUnloadNtfsMcbRange Mcb: A10_Mcb Completed.Operational
499Valid NTFS boot sector.Operational
500Not an NTFS boot sector.Operational
501NtfsMountVolume: Vcb:A10_Vcb, IC:A11_IrpContext, Growing allocation for Mft's …Operational
502NtfsMountVolume: IC: %1, Vcb: %2, Label: %3, DeviceName: %4.Operational
503Mounting DAX partition.Operational
504DAX volume mounted without DAX support because storage is not DAX capable.Operational
505NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Mft …Operational
506NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Converting …Operational
507NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext, …Operational
508Unexpected exception code of 0xA10_ExceptionCode received.Operational
509Exception code of 0xA10_ExceptionCode received during mount.Operational
510Unexpected exception code of 0xA10_ExceptionCode received.Operational
511LogFileFull A10_IrpContext->LogFullReason BackTrace: ln A11_BackTrace[0]; ln …Operational
512Unexpected raise of 0xA10_ExceptionCode during critical non-raise code.Operational
513NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!Operational
514NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!Operational
515Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb …Operational
516Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb …Operational
517Setting STATUS_CANT_WAIT in top-level exception status for write @ …Operational
518Setting 0xA10_ExceptionCode in top-level exception status for write @ …Operational
519[A10_IrpSp->MajorFunction, A11_IrpSp->MinorFunction!Operational
520[A10_IrpSp->MajorFunction, A11_IrpSp->MinorFunction!Operational
521Can't handle invalid bitmap in a positive way.Operational
522NTFS ETW tracing is now active.Operational
523Updating NtfsMinTrimTotalSize to A10_MinTrimTotalSize.Operational
524Updating NtfsMaxTrimTotalSize to A10_MaxTrimTotalSize.Operational
525NtfsSetObjectId: Caller does not have restore access.Operational
526NtfsSetObjectIdExtendedInfo: Caller does not have write access.Operational
527NtfsDeleteObjectId: Caller does not have write access.Operational
528A10___FUNCTION__: Setting RM at 0xA11_(PVOID)Vcb->TxfVcb.DefaultRm …Operational
529NtfsFsQuotaSetInfo: Denying access due to administrator limit.Operational
530NtfsCommonSetQuota: Caller does not have manage volume privilege and it's not …Operational
531Unexpected Paging-Read on DAX mappable stream, Scb=A10_Scb.Operational
532NtfsSetReparsePoint: Caller does not have write access.Operational
533NtfsSetReparsePointEx: Caller does not have write access.Operational
534NtfsDeleteReparsePoint: Caller does not have write access.Operational
535NtfsAbortTransaction IC: A10_IrpContext, TransactionId: …Operational
536NtfsAbortTransaction IC: A10_IrpContext, TransactionId: …Operational
537DoAction::InitializeFRS IC:A10_IrpContext, …Operational
538DoAction::DeallocateFRS IC:A10_IrpContext, …Operational
539DoAction::WriteEndOfFRS IC:A10_IrpContext, …Operational
540DoAction::CreateAttribute IC:A10_IrpContext, …Operational
541NtfsRestartChangeValue IC:A10_IrpContext, …Operational
542DoAction::SetNewAttributeSizes IC:A10_IrpContext, …Operational
543DoAction(SetBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: …Operational
544DoAction(ClearBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: …Operational
545NtfsUpgradeFileSecurity: Denying access due to volume does not support Txf.Operational
546NtfsCaseSensitiveInfoAccessCheck: Caller does not have write access.Operational
547NtfsCaseSensitiveInfoAccessCheck: Caller does not have appropriate access.Operational
548NtfsCheckFileForDelete: Denying access due to there are same-tx handles open to …Operational
549NtfsCheckFileForDelete: Denying access due to TxfCheckForLockConflict failed.Operational
550NtfsCheckFileForDelete: Denying access due to superseding view indexes are not …Operational
551NtfsCheckFileForDelete: Denying access due to non-posix delete of target …Operational
552NtfsCheckFileForDelete: Denying access due to file is not deleteable.Operational
553NtfsCheckFileForDelete: Denying access due to target file is read only.Operational
554NtfsCheckFileForDelete: Caller does not have write attributes access …Operational
555NtfsCheckFileForDelete: Denying access due to failing to remove image section.Operational
556NtfsGlobalSdUpdate: Caller does not have manage volume privilege.Operational
557NtfsRepairItem: Denying access due to volume is locked.Operational
558NtfsSetRepairState: Caller does not have manage volume privilege.Operational
559NtfsInitiateRepair: Caller does not have manage volume privilege.Operational
560NTFS ETW tracing is shutting down.Operational
561NtfsDefineStorageReserve: Caller does not have manage volume privilege.Operational
562NtfsDeleteStorageReserve: Caller does not have manage volume privilege.Operational
563NtfsRepairStorageReserve: Caller does not have manage volume privilege.Operational
564NtfsSetStorageReserveIdInfo: System files are not allowed to be part of a …Operational
565NtfsSetStorageReserveIdInfo: Caller does not have appropriate access.Operational
566NtfsChangeStorageReserveId: Caller does not have manage volume privilege.Operational
567NtfsChangeStorageReserveId: Caller does not have manage volume privilege to …Operational
568Failed to get a non-volatile token for Vcb: A10_Vcb, Status: A11_Status.Operational
569Failed to free non-volatile token for Vcb: A10_Vcb, Status: A11_Status.Operational
570NtfsRestoreScbSnapshots: Restored TotalAllocated, Scb: A10_Scb, TotalAllocated: …Operational
571NtfsGetDeallocatedClusters: Lsn updated for DeallocatedClusters: …Operational
572ClustersLinkAsHead: A10_ClustersLinkAsHead, FlagsToMatch: 0xA11_FlagsToMatch, …Operational
573Clusters: A10_Clusters, Flags: 0xA11_Clusters->Flags.Operational
574Matching cluster: A10_Clusters, NumberOfRuns: 0xA11_NumberOfRuns.Operational
575Clusters: A10_Clusters.Operational
576Allocated new deallocated clusters.Operational
577Need to add Range.Operational
578Added range.Operational
579TxfCheckForLockConflict: File locked for modify transaction.Operational
580TxfCheckForLockConflict: Locking transaction is doomed and caller is non-trans …Operational
581TxfCheckForLockConflict: Modification access desired.Operational
582TxfCheckForLockConflict: File has user handle opened on one of the versions or …Operational
583A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) …Operational
584A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) …Operational
585A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting …Operational
586A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting …Operational
587A10___FUNCTION__: RM at 0xA11_(PVOID)CalloutParameters->TxfFlush.TxfRmcb …Operational
588A10___FUNCTION__: TxfStartRm reports RM will be reset: RM metadata corrupt.Operational
589A10___FUNCTION__: TxfStartRm reports RM will be reset: TM could not be …Operational
590A10___FUNCTION__: TxfStartRm reports RM will be reset: RM log corrupt.Operational
591A10___FUNCTION__: TxfStartRm reports RM will be reset: log version changed.Operational
592A10___FUNCTION__: TxfStartRm reports RM will be reset: dedicated log found, need …Operational
593A10___FUNCTION__: TxfStartRm reports RM will be reset: multiplexed log found, …Operational
594A10___FUNCTION__: TxfStartRm reports RM will be reset: CLFS log metadata …Operational
595A10___FUNCTION__: TxfStartRm reports RM will be reset: 0xA11_FailureStatus.Operational
596A10___FUNCTION__: RM did not start and WILL NOT be reset, status code is …Operational
597A10___FUNCTION__: Could not initialize IrpContext: 0xA11_Status.Operational
598TxfInitializeVolume: Denying access due to Txf start is not allowed (possible …Operational
599A10___FUNCTION__: IOCTL_VOLUME_GET_GPT_ATTRIBUTES returned 0xA11_TempStatus for …Operational
600A10___FUNCTION__: Exception code 0xA11_GetExceptionCode(), Status 0xA12_Status …Operational
601A10___FUNCTION__: Couldn't reset default RM on VCB at 0xA11_(PVOID)Vcb after …Operational
602A10___FUNCTION__: Exception 0xA11_GetExceptionCode() raised from …Operational
603A10___FUNCTION__: A11_(NT_SUCCESS( Status ) ? 'Succeeded' : 'FAILED') …Operational
604A10___FUNCTION__: Attempting auto-restart of RM at 0xA11_(PVOID)TxfRmcb …Operational
605A10___FUNCTION__: Volume too small to start RM at 0xA11_(PVOID)TxfRmcb …Operational
606A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
607TxfStartRm: Denying access due to Txf start is not allowed (possible racing with …Operational
608A10___FUNCTION__: Raising to reset RM at 0xA11_(PVOID)TxfRmcb …Operational
609TxfStartRm: Denying access due to Txf start is not allowed (possible racing with …Operational
610A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: no …Operational
611A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Different …Operational
612A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
613A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
614A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: RmID …Operational
615A10___FUNCTION__: Got A11_Status from ClfsGetLogFileInformation for RM at …Operational
616A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
617A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
618A10___FUNCTION__: TxF RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} started …Operational
619A10___FUNCTION__: TxF RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} failed to …Operational
620A10___FUNCTION__: Shutting down A11_(TxfIsDefaultRm( TxfRmcb ) ? 'default' : …Operational
621A10___FUNCTION__: Setting RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} up for …Operational
622TxfFlushAndInvalidateExistingStructures: File has open user handles.Operational
623(A10_FILEID_FROM_SOURCE( FileNLine ):A11_LINENUM_FROM_SOURCE( FileNLine )) - …Operational
624A10___FUNCTION__: Renamed RM at 0xA11_(PVOID)TxfRmcb from {A12__OldGuid} to …Operational
625A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}, rolling back …Operational
626A10___FUNCTION__: Renamed RM at 0xA11_(PVOID)TxfRmcb from {A12__OldGuid} to …Operational
627TxfFsctlStartRm: Denying access due starting default RM is not allowed.Operational
628TxfFsctlWriteBackupInformation: Denying access due RM is active.Operational
629A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found …Operational
630A10___FUNCTION__: Error Setting Delete Disposition: 0xA11_Status FileObject: …Operational
631A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Got a …Operational
632TxfSetupTransactionContextFromCcb: Modifying operation is now allowed with a …Operational
633TxfSetupTransactionContextFromCcb: Invalid TxF structure.Operational
634TxfSetupTransactionContextFromCcb: Denying access of modifying operation on a …Operational
635A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} raising …Operational
636A10___FUNCTION__: Commit (0xA11_TransactionNotification) …Operational
637A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting …Operational
638A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting …Operational
639A10___FUNCTION__: Error doing IRP_MJ_FLUSH_BUFFERS on RM at …Operational
640A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} trying to …Operational
641A10___FUNCTION__: Aborting call stack: 0xA11_CallStack[0] 0xA12_CallStack[1] …Operational
642A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting …Operational
643A10___FUNCTION__: 0xA11_Status initializing IrpContext for tx at …Operational
644A10___FUNCTION__: 0xA11_Status writing log record for RM at 0xA12_(PVOID)TxfRmcb …Operational
645A10___FUNCTION__: About to force aborts on RM at 0xA11_(PVOID)TxfRmcb …Operational
646A10___FUNCTION__: BaseLsn is greater than TargetLsn on RM at …Operational
647A10___FUNCTION__: No transactions remain on RM at 0xA11_(PVOID)TxfRmcb …Operational
648A10___FUNCTION__: Transaction's first undo LSN greater than TargetLsn on RM at …Operational
649A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} …Operational
650A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} got …Operational
651A10___FUNCTION__: Inactive RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.Operational
652A10___FUNCTION__: Log is pinned on RM at 0xA11_(PVOID)TxfRmcb …Operational
653A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}, rolling back …Operational
654A10___FUNCTION__: Log pinned trying to advance RestartLsn on RM at …Operational
655A10___FUNCTION__: Log pinned by doomed transaction on RM at 0xA11_(PVOID)TxfRmcb …Operational
656A10___FUNCTION__: Reporting 0xA11_PinnedStatus to CLFS from RM at …Operational
657A10___FUNCTION__: Done forcing aborts on RM at 0xA11_(PVOID)TxfRmcb …Operational
658A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Txf …Operational
659A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found …Operational
660A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found …Operational
661A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
662A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
663A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found …Operational
664A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
665A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops …Operational
666A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops …Operational
667A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops …Operational
668A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
669A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
670A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops …Operational
671A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Could …Operational
672A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops …Operational
673A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops …Operational
674A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
675A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Epoch …Operational
676A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: …Operational
677NtfsReadUsnJournal: Caller does not have manage volume privilege.Operational
678TrimUsnJournal (A10_Vcb, A11_IrpContext): Decided to trim usn journal.Operational
679TrimUsnJournal (A10_Vcb, A11_IrpContext): About to delete allocation till …Operational
680TrimUsnJournal (A10_Vcb, A11_IrpContext): Before trimming journal AS …Operational
681TrimUsnJournal (A10_Vcb, A11_IrpContext): After trimming journal AS …Operational
682TrimUsnJournal (A10_Vcb, A11_IrpContext): Mapping pairs validated.Operational
683TrimUsnJournal (A10_Vcb, A11_IrpContext): Checkpointed.Operational
684NtfsQueryUsnJournal: Denying access due to NULL Ccb.Operational
685NtfsDeleteUsnJournal: Caller does not have manage volume access.Operational
686NtfsRestartUsnJournal: Caller does not have manage volume privilege.Operational
687NtOfsCreateAttributeEx: Stream already has a open user handle.Operational
688OfsSetLength …Operational
689OfsSetLength …Operational
690OfsSetLength …Operational
691OfsSetLength …Operational
692NtOfsPostNewLength …Operational
693NtfsIsRegionDangling: RemainingClusterCount: 0xA10_RemainingClusterCount!Operational
694Vcb A10_Vcb - has *no* active PFNs.Operational
695Vcb A10_Vcb - failed to query active PFNs assuming there are some.Operational
696Vcb A10_Vcb - has active PFNs.Operational
697NtfsPerformDismountOnVcb: Vcb A10_Vcb.Operational
698NtfsPerformDismountOnVcb: Vcb A10_Vcb - Found frozen deallocated clusters.Operational
699NtfsPerformDismountOnVcb: Vcb A10_Vcb - Wait for any on going trim to finish.Operational
700NtfsPerformDismountOnVcb: Vcb A10_Vcb - No more on going trim.Operational
701NtfsPerformDismountOnVcb: IC: %1, Vcb: %2, Label: %3, DeviceName: %4.Operational
702NtfsPostVcbIsCorrupt.Operational
703NtfsPostVcbIsCorrupt: Marking volume dirty.Operational
704NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for …Operational
705NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for …Operational
706Succeeding log write @ 0xA10_IrpSp->Parameters.Write.ByteOffset.HighPart!Operational
707Unexpected Paging-Write on stream accessed in Direct-Access mode, Scb=A10_Scb.Operational
708NtfsCommonWrite: Writing beyond highest writable sector on active volume is not …Operational
709Ignoring write to 0xA10_StartingVbo!Operational
710Truncating write from 0xA10_ByteRange!Operational

Event ID 10 — NtfsLookupRealAllocation: Vcn A10_Vcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLookupRealAllocation: Vcn %1!I64x!, LowestVcn %2!I64x!, HighestVcn %3!I64x!, AllocationClusters %4!I64x!

Fields #

NameDescription
A10_Vcn HexInt64 → HexInt64
A11_Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64
A12_Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64
A13_AllocationClusters HexInt64 → HexInt64

Event ID 11 — NtfsAllocateAttribute MaxAlloc for Mft's AttrList IC:A10_IrpContext, Scb:A11_Scb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateAttribute MaxAlloc for Mft's AttrList IC:%1!p!, Scb:%2!p!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Scb Pointer → HexInt64

Event ID 12 — FileObject: A10_FileObject, Scb: A11_Scb, StaringVcn: A12_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FileObject: %1!p!, Scb: %2!p!, StaringVcn: %3!I64x!, ClusterCount: %4!I64x!, Flags: %5!08x!, CcbForWriteExtend: %6!p!

Fields #

NameDescription
A10_FileObject Pointer → HexInt64
A11_Scb Pointer → HexInt64
A12_StartingVcn HexInt64 → HexInt64
A13_ClusterCount HexInt64 → HexInt64
A14_Flags HexInt32 → HexInt32
A15_CcbForWriteExtend Pointer → HexInt64

Event ID 13 — NtfsAddAllocation IC:A10_IrpContext, FileObject:A11_FileObject, Scb:A12_Scb, StaringVcn:A13_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddAllocation IC:%1!p!, FileObject:%2!p!, Scb:%3!p!, StaringVcn:%4!I64x!, ClusterCount:%5!I64x!, Flags:%6!08x!, CcbForWriteExtend:%7!p!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_FileObject Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_StartingVcn HexInt64 → HexInt64
A14_ClusterCount HexInt64 → HexInt64
A15_Flags HexInt32 → HexInt32
A16_CcbForWriteExtend Pointer → HexInt64

Event ID 14 — Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Purge failed: Scb: %1!p!, PurgeOffset: 0x%2!016I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_PurgeOffset HexInt64 → HexInt64

Event ID 15 — Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Purge failed: Scb: %1!p!, PurgeOffset: 0x%2!016I64x!, PurgeChunkLength: 0x%3!x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_PurgeOffset HexInt64 → HexInt64
A12_PurgeChunkLength HexInt32 → HexInt32

Event ID 16 — NtfsGetLastVcnForNewMappingPairSize IC:A10_IrpContext, Using LastVcn:A11_*LastVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGetLastVcnForNewMappingPairSize IC:%1!p!, Using LastVcn:%2!4I64x!, InstanceId:%3!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_*LastVcn HexInt64 → HexInt64
A12_Attribute->Instance HexInt32 → HexInt32

Event ID 17 — Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber( _Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Can't find StdInfo in FileRef %1!I64x!

Fields #

NameDescription
A10_NtfsFullFileRefNumber( _Fcb->FileReference ) HexInt64 → HexInt64

Event ID 18 — Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber( _Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Can't find StdInfo in FileRef %1!I64x!

Fields #

NameDescription
A10_NtfsFullFileRefNumber( _Fcb->FileReference ) HexInt64 → HexInt64

Event ID 19 — NtfsCreateNonresidentWithValue Create Mft's NonResident Attribute List IC:A10_IrpContextValueLength:A11_ValueLength, AttrFlags=A12_AttributeFlags.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCreateNonresidentWithValue Create Mft's NonResident Attribute List IC:%1!p!ValueLength:%2!x!, AttrFlags=%3!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_ValueLength HexInt32 → HexInt32
A12_AttributeFlags HexInt32 → HexInt32

Event ID 20 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddAttributeAllocation(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, LastVcn %5!I64x!, NewHighestVcn %6!I64x!, PassCount %7!x! - step 6

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_LastVcn HexInt64 → HexInt64
A15_NewHighestVcn HexInt64 → HexInt64
A16_PassCount HexInt32 → HexInt32

Event ID 21 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddAttributeAllocation(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, LowestVcn %5!I64x!, HighestVcn %6!I64x!, ALE.LowestVcn %7!I64x! - try to merge backward

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64

Event ID 22 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddAttributeAllocation(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, LowestVcn %5!I64x!, HighestVcn %6!I64x!, ALE.LowestVcn %7!I64x! - after merge backward

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64

Event ID 23 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddAttributeAllocation(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, LowestVcn %5!I64x!, HighestVcn %6!I64x!, ALE.LowestVcn %7!I64x!, PassCount %8!x! - before last merge after step 6

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64
A17_PassCount HexInt32 → HexInt32

Event ID 24 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddAttributeAllocation(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, LowestVcn %5!I64x!, HighestVcn %6!I64x!, ALE.LowestVcn %7!I64x! - after last merge after step 6

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64

Event ID 25 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddAttributeAllocation(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, MergeSkipCt %5!x! - done

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NtfsFrsConsolidationStatistics.MergeSkipCount HexInt32 → HexInt32

Event ID 26 — NtfsRestartRemoveAttribute FileRef:0xA10_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestartRemoveAttribute FileRef:0x%1!04x!_%2!08x!, BaseFRS:0x%3!012I64x!, Attrib:0x%4!x!

Fields #

NameDescription
A10_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A11_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A12_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64
A13_Attribute->TypeCode HexInt32 → HexInt32

Event ID 27 — NtfsRestartChangeValue FileRef:0xA10_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestartChangeValue FileRef:0x%1!04x!_%2!08x!, BaseFRS:0x%3!012I64x!, Attrib:0x%4!x!

Fields #

NameDescription
A10_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A11_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A12_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64
A13_Attribute->TypeCode HexInt32 → HexInt32

Event ID 28 — AddToAttributeList(A10_Fcb->Vcb,A11_IrpContext): FRef A12_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

AddToAttributeList(%1!p!,%2!p!): FRef %3!I64x!, OldSig %4!x!, OldLCS %5!x!, NewLCS %6!x!

Fields #

NameDescription
A10_Fcb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64
A13_StdInfoAttrListEntry->Signature HexInt32 → HexInt32
A14_StdInfoAttrListEntry->LastCompactedSize HexInt32 → HexInt32
A15_CurrentAttributeListSize HexInt32 → HexInt32

Event ID 29 — DeleteFromAttributeList(A10_Fcb->Vcb,A11_IrpContext): FRef A12_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DeleteFromAttributeList(%1!p!,%2!p!): FRef %3!I64x!, OldSig %4!x!, OldLCS %5!x!, NewLCS %6!x!

Fields #

NameDescription
A10_Fcb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64
A13_StdInfoAttrListEntry->Signature HexInt32 → HexInt32
A14_StdInfoAttrListEntry->LastCompactedSize HexInt32 → HexInt32
A15_NewStdInfoAttrListEntry.LastCompactedSize HexInt32 → HexInt32

Event ID 30 — MakeRoomForAttribute Moving Mft's attribute IC:A10_IrpContext, Moving Attrib A11_i/A12_MAX_MOVEABLE_ATTRIBUTES, Type=A13_Attribute->TypeCode, RecLengh=A14_Attribute->RecordLength, Instance:A15_Attr...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MakeRoomForAttribute Moving Mft's attribute IC:%1!p!, Moving Attrib %2!x!/%3!x!, Type=%4!x!, RecLengh=%5!x!, Instance:%6!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_i HexInt32 → HexInt32
A12_MAX_MOVEABLE_ATTRIBUTES HexInt32 → HexInt32
A13_Attribute->TypeCode HexInt32 → HexInt32
A14_Attribute->RecordLength HexInt32 → HexInt32
A15_Attribute->Instance HexInt32 → HexInt32

Event ID 31 — MoveAttributeToOwnRecord Moving Mft's $BITMAP IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, TypeCode:A12_Attribute->TypeCode, RecLen:A13_Attribute->RecordLength, Form:A14_Attribute->FormCode, Insta...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MoveAttributeToOwnRecord Moving Mft's $BITMAP IC:%1!p!, SizeNeeded:%2!x!, TypeCode:%3!x!, RecLen:%4!x!, Form:%5!x!, Instance:%6!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_SizeNeeded HexInt32 → HexInt32
A12_Attribute->TypeCode HexInt32 → HexInt32
A13_Attribute->RecordLength HexInt32 → HexInt32
A14_Attribute->FormCode HexInt32 → HexInt32
A15_Attribute->Instance HexInt32 → HexInt32

Event ID 32 — MoveAttributeToOwnRecord IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, Bytes2Free:A12_BytesToFree, OldMappingSize:A13_MappingPairSize, NewMappingSize:A14_NewMappingPairSize.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MoveAttributeToOwnRecord IC:%1!p!, SizeNeeded:%2!x!, Bytes2Free:%3!x!, OldMappingSize:%4!x!, NewMappingSize:%5!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_SizeNeeded HexInt32 → HexInt32
A12_BytesToFree HexInt32 → HexInt32
A13_MappingPairSize HexInt32 → HexInt32
A14_NewMappingPairSize HexInt32 → HexInt32

Event ID 33 — NtfsRestartZeroEndOfFileRecord FileRef:0xA10_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestartZeroEndOfFileRecord FileRef:0x%1!04x!_%2!08x!, BaseFRS:0x%3!012I64x!, Start:0x%4!x!, Len:0x%5!x!

Fields #

NameDescription
A10_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A11_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A12_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64
A13_StartZero HexInt32 → HexInt32
A14_ZeroLength HexInt32 → HexInt32

Event ID 34 — MergeFRS2(%1,%2): Scb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, TypeCode %5!x!, AttrName %6!S!, LowVcn %7!I64x!, HalfWayVcn %8!I64x!, FinalVcn %9!I64x!, PackedMode %10!x!, TryPrior %11!x! - about to merge

Event ID 35 — MergeFRS2(%1,%2): Scb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, TypeCode %5!x!, AttrName %6!S!, DeleteFileRef %7!x!0000%8!08x!, LowVcn %9!I64x!, LastVcn %10!I64x!, FinalVcn %11!I64x! - all fit in one so get rid of the second one

Event ID 36 — MergeFRS2(%1,%2): Scb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, TypeCode %5!x!, AttrName %6!S!, DeleteFileRef %7!x!0000%8!08x!, LowVcn %9!I64x!, LastVcn %10!I64x!, FinalVcn %11!I64x! - should all fit into one so get rid of the second one FIRST

Event ID 37 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, Vcn %5!I64x! - initial RangePtr query

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NewFinalVcn HexInt64 → HexInt64

Event ID 38 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, Vcn %5!I64x!, Rptr %6!p! - secondary RangePtr query

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NewHalfWayVcn HexInt64 → HexInt64
A15_RangePtr Pointer → HexInt64

Event ID 39 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, Vcn %5!I64x!, Rptr %6!p! - calling lookup runs range

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NewHalfWayVcn HexInt64 → HexInt64
A15_RangePtr Pointer → HexInt64

Event ID 40 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, McbArray %5!p! (%6!I64x!, %7!I64x!) - current McbArray

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NtfsMcbArray Pointer → HexInt64
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64

Event ID 41 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, McbArray %5!p! (%6!I64x!, %7!I64x!) - previous McbArray

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NtfsMcbArray Pointer → HexInt64
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64

Event ID 42 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, McbArray %5!p! (%6!I64x!, %7!I64x!) - prev prev McbArray

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NtfsMcbArray Pointer → HexInt64
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64

Event ID 43 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, McbArray %5!p! (%6!I64x!, %7!I64x!) - next McbArray

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NtfsMcbArray Pointer → HexInt64
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64

Event ID 44 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, NewFinalVcnInMcb %5!I64x! > NewFinalVcn %6!I64x! - NewFinalVcn is smaller

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NewFinalVcnInMcb HexInt64 → HexInt64
A15_NewFinalVcn HexInt64 → HexInt64

Event ID 45 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, NewStartVcn %5!I64x!, LastVcn %6!I64x!, NewFinalVcn %7!I64x!, NewFinalVcnInMcb %8!I64x!, #Ranges %9!x!, DeletedNextAttribute %10!x!, Mcb1(%11!x!,%12!x!), Mcb2(%13!x!,%14!x!), McbArraySizeInUseChange %15!d! - final vcn in mcb

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NewStartVcn HexInt64 → HexInt64
A15_LastVcn HexInt64 → HexInt64
A16_NewFinalVcn HexInt64 → HexInt64
A17_NewFinalVcnInMcb HexInt64 → HexInt64
A18_NumberOfRanges HexInt32 → HexInt32
A19_DeletedNextAttribute HexInt32 → HexInt32
A20_Mcb1StartWithNewStartVcn HexInt32 → HexInt32
A21_Mcb1HoldNewStartVcn HexInt32 → HexInt32
A22_Mcb2StartWithNewStartVcn HexInt32 → HexInt32
A23_Mcb2HoldNewStartVcn HexInt32 → HexInt32
A24_McbArraySizeInUseChange Int32 → int

Event ID 46 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, StartingVcn %5!I64x!, EndingVcn %6!I64x! - redefined mcb range1

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_NewStartVcn HexInt64 → HexInt64
A15_DeletedNextAttribute ? NewFinalVcnInMcb : (LastVcn-1) HexInt64 → HexInt64

Event ID 47 — MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

MergeFRS2(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, StartingVcn %5!I64x!, EndingVcn %6!I64x! - redefined mcb range2

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A14_LastVcn HexInt64 → HexInt64
A15_NewFinalVcnInMcb HexInt64 → HexInt64

Event ID 48 — RedoAttribute(%1,%2): Scb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

RedoAttribute(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, TypeCode %5!x!, AttrName %6!S!, FileRef %7!I64x!, OldLowVcn %8!I64x!, NewLowVcn %9!I64x!, Instance %10!x! - updating LowestVcn in attribute list entry

Event ID 49 — RedoAttribute(%1,%2): Scb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

RedoAttribute(%1!p!,%2!p!): Scb %3!p!, FileRef %4!I64x!, TypeCode %5!x!, AttrName %6!S!, OldLowVcn %7!I64x!, NewLowVcn %8!I64x!, OldHighVcn %9!I64x!, NewHighVcn %10!I64x!, ChildRef %11!x!0000%12!08x! - done

Event ID 50 — NtfsConsolidateAllFileRecords: Invalid Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords: Invalid Vcb. Thread: %1!p!.

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64

Event ID 51 — NtfsConsolidateAllFileRecords: Volume is locked.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords: Volume is locked. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Volume Id: %5!S!, Vcb State: 0x%6!08x!.

Event ID 52 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x!, FirstRequest %5!x! - opened fcb

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64
A14_AllFlags.FirstRequest HexInt32 → HexInt32

Event ID 53 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x! - already in progress so get out

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64

Event ID 54 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x! - set in progress flag

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64

Event ID 55 — NtfsConsolidateAllFileRecords(%1,%2): Fcb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x!, RstrTypeCode %5!x!, RstrAttrName %6!S!, RstrVcn %7!I64x!, RstrAttrListEntryOffset %8!x!, AttrListEntryOffset %9!x!, AttrListLength %10!I64x!, AttrListGrowBy %11!x!(%12!d!) - adjust FinalCompactedSizeDeduction

Event ID 56 — NtfsConsolidateAllFileRecords(%1,%2): Fcb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x!, TypeCode %5!x!, AttrName %6!S!, Vcn %7!I64x!, Instance %8!x!, RstrAttrListEntryOffset %9!x!, AttrListLength %10!I64x! - breaking up 1

Event ID 57 — NtfsConsolidateAllFileRecords(%1,%2): Fcb %3, FileRef %4!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x!, TypeCode %5!x!, AttrName %6!S!, Vcn %7!I64x!, Instance %8!x!, RstrAttrListEntryOffset %9!x!, AttrListLength %10!I64x! - breaking up 2

Event ID 58 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x!, Scb %5!p! - completed this Scb

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64
A14_Scb Pointer → HexInt64

Event ID 59 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x! - going into finally

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64

Event ID 60 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): FileRef A12_*(PULONGLONG)_FrsConsolidationContext->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): FileRef %3!I64x!, Status %4!x! - Abnormal Termination

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_*(PULONGLONG)_FrsConsolidationContext->FileReference HexInt64 → HexInt64
A13_IrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 61 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x! - decremented close counts

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64

Event ID 62 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x! - clearing in progress flag

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64

Event ID 63 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_FileRef!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x!, ExceptionStatus %5!x!- released

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_FileRef HexInt64 → HexInt64
A14_ExceptionStatus HexInt32 → HexInt32

Event ID 64 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_FileRef!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): Fcb %3!p!, FileRef %4!I64x!, RemovedFcb %5!x!, AllFlags.FcbAcquired %6!x!, TransId %7!x! - no release

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_FileRef HexInt64 → HexInt64
A14_RemovedFcb HexInt32 → HexInt32
A15_AllFlags.FcbAcquired HexInt32 → HexInt32
A16_IrpContext->TransactionId HexInt32 → HexInt32

Event ID 65 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): DeltaTime A12_(EndTime.QuadPart*1000)/NtfsPerformanceFrequency.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsConsolidateAllFileRecords(%1!p!,%2!p!): DeltaTime %3!I64d! (ms), TotalTime %4!I64d! (ms)

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_(EndTime.QuadPart*1000)/NtfsPerformanceFrequency.QuadPart Int64 → long
A13_(FrsConsolidationContext->TotalTime*1000)/NtfsPerformanceFrequency.QuadPart Int64 → long

Event ID 66 — UpdateLCS: Vcb A10_Fcb->Vcb, IC A11_IrpContext, FRef A12_*(PULONGLONG)_Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

UpdateLCS: Vcb %1!p!, IC %2!p!, FRef %3!I64x!, OldSig %4!x!, OldLCS %5!x!, NewLCS %6!x!

Fields #

NameDescription
A10_Fcb->Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64
A13_StdInfoAttrListEntry->Signature HexInt32 → HexInt32
A14_StdInfoAttrListEntry->LastCompactedSize HexInt32 → HexInt32
A15_AttributeListSize HexInt32 → HexInt32

Event ID 67 — NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, Vcn: 0xA14_OriginalStartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateClustersPriv IC: %1!p!, Vcb: %2!p!, Scb: %3!p!, Mcb: %4!p!, Vcn: 0x%5!I64x!, Length: 0x%6!I64x!, AllocateAll: %7!S!, TargetLcn: 0x%8!I64x!, PreAllocated: %9!S!, DelayedAllocation: %10!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13__Scb->Mcb Pointer → HexInt64
A14_OriginalStartingVcn HexInt64 → HexInt64
A15_ClusterCount HexInt64 → HexInt64
A16_AllocateAll UInt32 → unsignedInt
A17_(TargetLcn != NULL) ? *TargetLcn : (ULONGLONG)-1 HexInt64 → HexInt64
A18_PreAllocated UInt32 → unsignedInt
A19_UseDelayedAllocation UInt32 → unsignedInt

Event ID 68 — NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, Vcn: 0xA14_OriginalStartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateClustersPriv IC: %1!p!, Vcb: %2!p!, Scb: %3!p!, Mcb: %4!p!, Vcn: 0x%5!I64x!, Length: 0x%6!I64x!, AllocateAll: %7!S!, TargetLcn: 0x%8!I64x!, PreAllocated: %9!S!, DelayedAllocation: %10!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13__Scb->Mcb Pointer → HexInt64
A14_OriginalStartingVcn HexInt64 → HexInt64
A15_ClusterCount HexInt64 → HexInt64
A16_AllocateAll UInt32 → unsignedInt
A17_(TargetLcn != NULL) ? *TargetLcn : (ULONGLONG)-1 HexInt64 → HexInt64
A18_PreAllocated UInt32 → unsignedInt
A19_UseDelayedAllocation UInt32 → unsignedInt

Event ID 69 — NtfsAllocateClustersPriv: Incremented TotalAllocated by 0xA10_FoundClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateClustersPriv: Incremented TotalAllocated by 0x%1!I64x! clusters, Scb: %2!p!, TotalAllocated: 0x%3!I64x!

Fields #

NameDescription
A10_FoundClusterCount HexInt64 → HexInt64
A11_Scb Pointer → HexInt64
A12_Scb->TotalAllocated HexInt64 → HexInt64

Event ID 70 — NtfsAllocateClustersPriv: Skipped incrementing TotalAllocated by 0xA10_FoundClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateClustersPriv: Skipped incrementing TotalAllocated by 0x%1!I64x! clusters, Scb: %2!p!, TotalAllocated: 0x%3!I64x!ScbState: %4!08x!, IrpContextState2: %5!08x!, AllocateWithNoHole: %6!d!

Fields #

NameDescription
A10_FoundClusterCount HexInt64 → HexInt64
A11_Scb Pointer → HexInt64
A12_Scb->TotalAllocated HexInt64 → HexInt64
A13_Scb->State HexInt32 → HexInt32
A14_IrpContext->State2 HexInt32 → HexInt32
A15_AllocateWithNoHole Int32 → int

Event ID 71 — NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: A11_ClustersAllocated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateClustersPriv IC: %1!p!, ClustersAllocated: %2!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_ClustersAllocated UInt32 → unsignedInt

Event ID 72 — NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: A11_ClustersAllocated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateClustersPriv IC: %1!p!, ClustersAllocated: %2!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_ClustersAllocated UInt32 → unsignedInt

Event ID 73 — NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, StartVcn: 0xA14_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters IC: %1!p!, Vcb: %2!p!, Scb: %3!p!, Mcb: %4!p!, StartVcn: 0x%5!I64x!, EndVcn: 0x%6!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13__Scb->Mcb Pointer → HexInt64
A14_StartingVcn HexInt64 → HexInt64
A15_EndingVcn HexInt64 → HexInt64

Event ID 74 — NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters: Vcb %1!p! - deleting FR %2!I64x! from clusters %3!I64x! to %4!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A12_StartingVcn HexInt64 → HexInt64
A13_EndingVcn HexInt64 → HexInt64

Event ID 75 — NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, StartVcn: 0xA14_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters IC: %1!p!, Vcb: %2!p!, Scb: %3!p!, Mcb: %4!p!, StartVcn: 0x%5!I64x!, EndVcn: 0x%6!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13__Scb->Mcb Pointer → HexInt64
A14_StartingVcn HexInt64 → HexInt64
A15_EndingVcn HexInt64 → HexInt64

Event ID 76 — NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_*(PULONGLONG)_Scb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters: Vcb %1!p! - deleting FR %2!I64x! starting at %3!I64x! for %4!I64x! clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64
A12_AdjLcn HexInt64 → HexInt64
A13_AdjClusterCount HexInt64 → HexInt64

Event ID 77 — NtfsDeallocateClusters: Vcb A10_Vcb - raising logfile full.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters: Vcb %1!p! - raising logfile full

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 78 — NtfsDeallocateClusters: Vcb A10_Vcb - adding clusters to DeallocatedClusters: A11_DeallocatedClusters ==> Lsn: A12_DeallocatedClusters->Lsn.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters: Vcb %1!p! - adding clusters to DeallocatedClusters: %2!p! ==> Lsn: %3!I64x!, ClusterCount: %4!I64x!, Flags: %5!08x!; Vcb's DeallocatedClustersCount old: %6!I64x! new: %7!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_DeallocatedClusters Pointer → HexInt64
A12_DeallocatedClusters->Lsn.QuadPart HexInt64 → HexInt64
A13_DeallocatedClusters->ClusterCount HexInt64 → HexInt64
A14_DeallocatedClusters->Flags HexInt32 → HexInt32
A15_Vcb->DeallocatedClusters HexInt64 → HexInt64
A16_Vcb->DeallocatedClusters + AdjClusterCount HexInt64 → HexInt64

Event ID 79 — NtfsDeallocateClusters: Decremented TotalAllocated by 0xA10_ClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters: Decremented TotalAllocated by 0x%1!I64x! clusters, Scb: %2!p!, TotalAllocated: 0x%3!I64x!Addr(TotalAllocated): %4!p!

Fields #

NameDescription
A10_ClusterCount HexInt64 → HexInt64
A11_Scb Pointer → HexInt64
A12_*TotalAllocated HexInt64 → HexInt64
A13_TotalAllocated Pointer → HexInt64

Event ID 80 — NtfsDeallocateClusters: Skipped decrementing TotalAllocated by 0xA10_ClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters: Skipped decrementing TotalAllocated by 0x%1!I64x! clusters, Scb: %2!p!Addr(TotalAllocated): %3!p!, ScbState: %4!08x!, IrpContextState2: %5!08x!

Fields #

NameDescription
A10_ClusterCount HexInt64 → HexInt64
A11_Scb Pointer → HexInt64
A12_TotalAllocated Pointer → HexInt64
A13_Scb->State HexInt32 → HexInt32
A14_IrpContext->State2 HexInt32 → HexInt32

Event ID 81 — NtfsDeallocateClusters: Vcb A10_Vcb - Undoing some changes to DeallocatedClustersCount from A11_Vcb->DeallocatedClusters!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters: Vcb %1!p! - Undoing some changes to DeallocatedClustersCount from %2!I64x! to %3!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->DeallocatedClusters HexInt64 → HexInt64
A12_Vcb->DeallocatedClusters-ClustersRemoved HexInt64 → HexInt64

Event ID 82 — NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: A11_ClustersDeallocated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters IC: %1!p!, ClustersDeallocated: %2!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_ClustersDeallocated UInt32 → unsignedInt

Event ID 83 — NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: A11_ClustersDeallocated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeallocateClusters IC: %1!p!, ClustersDeallocated: %2!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_ClustersDeallocated UInt32 → unsignedInt

Event ID 84 — NtfsModifyBitsInBitmap IC: A10_IrpContext, Vcb: A11_Vcb, FirstBit: 0xA12_FirstBit!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsModifyBitsInBitmap IC: %1!p!, Vcb: %2!p!, FirstBit: 0x%3!I64x!, BeyondLastBit: 0x%4!I64x!, Redo: 0x%5!x!, Undo: 0x%6!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_FirstBit HexInt64 → HexInt64
A13_BeyondFinalBit HexInt64 → HexInt64
A14_RedoOperation HexInt32 → HexInt32
A15_UndoOperation HexInt32 → HexInt32

Event ID 85 — NtfsModifyBitsInBitmap IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsModifyBitsInBitmap IC: %1!p!, Bitmap: %2!p!, BaseLcn: 0x%3!I64x!, CurrentLcn: 0x%4!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11__Bitmap Pointer → HexInt64
A12_BaseLcn HexInt64 → HexInt64
A13_CurrentLcn HexInt64 → HexInt64

Event ID 86 — NtfsAllocateBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: 0xA12_StartingLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateBitmapRun IC: %1!p!, Vcb: %2!p!, StartingLcn: 0x%3!I64x!, ClusterCount: 0x%4!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_StartingLcn HexInt64 → HexInt64
A13_ClusterCount HexInt64 → HexInt64

Event ID 87 — NtfsAllocateBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAllocateBitmapRun IC: %1!p!, Bitmap: %2!p!, BaseLcn: 0x%3!I64x!, StartingLcn: 0x%4!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11__Bitmap Pointer → HexInt64
A12_BaseLcn HexInt64 → HexInt64
A13_StartingLcn HexInt64 → HexInt64

Event ID 88 — NtfsRestartSetBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, BitMapOffset: 0xA12_BitMapOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestartSetBitsInBitMap IC: %1!p!, Bitmap: %2!p!, BitMapOffset: 0x%3!08x!, NumBits: 0x%4!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Bitmap Pointer → HexInt64
A12_BitMapOffset HexInt32 → HexInt32
A13_NumberOfBits HexInt32 → HexInt32

Event ID 89 — NtfsFreeBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: 0xA12_StartingLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeBitmapRun IC: %1!p!, Vcb: %2!p!, StartingLcn: 0x%3!I64x!, ClusterCount: 0x%4!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_StartingLcn HexInt64 → HexInt64
A13_*ClusterCount HexInt64 → HexInt64

Event ID 90 — NtfsFreeBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeBitmapRun IC: %1!p!, Bitmap: %2!p!, BaseLcn: 0x%3!I64x!, StartingLcn: 0x%4!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11__Bitmap Pointer → HexInt64
A12_BaseLcn HexInt64 → HexInt64
A13_StartingLcn HexInt64 → HexInt64

Event ID 91 — NtfsRestartClearBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, BitMapOffset: 0xA12_BitMapOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestartClearBitsInBitMap IC: %1!p!, Bitmap: %2!p!, BitMapOffset: 0x%3!08x!, NumBits: 0x%4!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Bitmap Pointer → HexInt64
A12_BitMapOffset HexInt32 → HexInt32
A13_NumberOfBits HexInt32 → HexInt32

Event ID 92 — NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12_Bitmap, StartingBitmapLcn: 0xA13_StartingBitmapLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetOrClearBitsUsingBaseMcb IC: %1!p!, Vcb: %2!p!, Bitmap: %3!p!, StartingBitmapLcn: 0x%4!I64x!, SetBits: %5!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_Bitmap Pointer → HexInt64
A13_StartingBitmapLcn HexInt64 → HexInt64
A14_SetBits UInt32 → unsignedInt

Event ID 93 — NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Bitmap: A11_Bitmap, StartLcn: 0xA12_StartingBit!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetOrClearBitsUsingBaseMcb IC: %1!p!, Bitmap: %2!p!, StartLcn: 0x%3!I64x!, EndLcn: 0x%4!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Bitmap Pointer → HexInt64
A12_StartingBit HexInt64 → HexInt64
A13_EndingBit HexInt64 → HexInt64

Event ID 94 — NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Result: A11_Results.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetOrClearBitsUsingBaseMcb IC: %1!p!, Result: %2!S!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Results UInt32 → unsignedInt

Event ID 95 — System files not marked as in use in the MFT bitmap.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

System files not marked as in use in the MFT bitmap.  DWord offset %1!x!, value %2!x!.

Fields #

NameDescription
A10_i HexInt32 → HexInt32
A11_OriginalSystemBitmap[i / sizeof( OriginalSystemBitmap[0] )] HexInt32 → HexInt32

Event ID 96 — Length: 0 --> BinIndex : 0 - Unexpected length.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Length:        0 --> BinIndex :        0    - Unexpected length

Event ID 97 — Length: A10_Length!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Length: %1!8I64d! --> BinIndex : %2!8u!    - Key: %3!u!, BitPosition: %4!ld!, GroupIndex: %5!ld!, GroupShiftFactor: %6!ld!

Fields #

NameDescription
A10_Length Int64 → long
A11_BinIndex UInt32 → unsignedInt
A12_Key UInt32 → unsignedInt
A13_BitPosition Int32 → int
A14_GroupIndex Int32 → int
A15_GroupShiftFactor Int32 → int

Event ID 98 — Length: A10_Length!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Length: %1!8I64d! --> BinIndex : %2!8u!    - BinIndex was beyond TotalBins: %3!u! hence brought down

Fields #

NameDescription
A10_Length Int64 → long
A11_BinIndex UInt32 → unsignedInt
A12_TotalBins UInt32 → unsignedInt

Event ID 99 — BinIndex: A10_BinIndex!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

BinIndex: %1!8u! --> MaxLength: %2!8I64d!  - BinIndex is set to last bin or beyond, TotalBins: %3!u!

Fields #

NameDescription
A10_BinIndex UInt32 → unsignedInt
A11_MAXLONGLONG Int64 → long
A12_TotalBins UInt32 → unsignedInt

Event ID 100 — BinIndex: A10_BinIndex!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

BinIndex: %1!8u! --> MaxLength: %2!8I64d!  - GroupIndex: %3!ld!, RelativeBinIndex: %4!ld!, MaxKey: %5!u!

Fields #

NameDescription
A10_BinIndex UInt32 → unsignedInt
A11_MaxLength Int64 → long
A12_GroupIndex Int32 → int
A13_RelativeBinIndex Int32 → int
A14_MaxKey UInt32 → unsignedInt

Event ID 101 — BinGroupShift: A10_NtfsCachedRunBinGroupShift!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

BinGroupShift: %1!8ld!, BinGroupSize: %2!8u!, BinGroupMask: %3!8x!

Fields #

NameDescription
A10_NtfsCachedRunBinGroupShift Int32 → int
A11_NtfsCachedRunBinGroupSize UInt32 → unsignedInt
A12_NtfsCachedRunBinGroupMask HexInt32 → HexInt32

Event ID 102 — BinIndex: A10_BinIndex!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

BinIndex: %1!8u! --> MaxLength: %2!8I64u! (0x%3!8I64x!)

Fields #

NameDescription
A10_BinIndex UInt32 → unsignedInt
A11_MaxLength UInt64 → unsignedLong
A12_MaxLength HexInt64 → HexInt64

Event ID 103 — Searched committed allocations but didnt find enough free space.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Searched committed allocations but didnt find enough free space.  StartingCluster %1!I64x!, ClusterCount %2!I64x!, Committed %3!I64x!, Total %4!I64x!, Free %5!I64x!

Fields #

NameDescription
A10_StartingCluster HexInt64 → HexInt64
A11_ClusterCount HexInt64 → HexInt64
A12_Vcb->TotalClustersCommitted HexInt64 → HexInt64
A13_Vcb->TotalClusters HexInt64 → HexInt64
A14_Vcb->FreeClusters HexInt64 → HexInt64

Event ID 104 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): first bit 0xA11_FirstBitToClear, last bit 0xA12_BeyondLastBitToClear - 1.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveClustersFromTPMap: Vcb %1!p! - Clearing TP map bit(s): first bit 0x%2!X!, last bit 0x%3!X!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_FirstBitToClear HexInt32 → HexInt32
A12_BeyondLastBitToClear - 1 HexInt32 → HexInt32

Event ID 105 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no leading partial slab.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveClustersFromTPMap: Vcb %1!p! - Clearing TP map bit(s): no leading partial slab

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 106 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): leading partial slab returned - LCN A11_*FreeClusterBase1!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveClustersFromTPMap: Vcb %1!p! - Clearing TP map bit(s): leading partial slab returned - LCN %2!I64X!, len %3!I64X!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_*FreeClusterBase1 HexInt64 → HexInt64
A12_*FreeClusterCount1 HexInt64 → HexInt64

Event ID 107 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no trailing partial slab.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveClustersFromTPMap: Vcb %1!p! - Clearing TP map bit(s): no trailing partial slab

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 108 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): trailing partial slab returned - lcn A11_*FreeClusterBase2!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveClustersFromTPMap: Vcb %1!p! - Clearing TP map bit(s): trailing partial slab returned - lcn %2!I64X!, len %3!I64X!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_*FreeClusterBase2 HexInt64 → HexInt64
A12_*FreeClusterCount2 HexInt64 → HexInt64

Event ID 109 — NtfsValidateTotalClustersCommitted(A10_Vcb,A11_PsGetCurrentThread()): TCC A12_Vcb->TotalClustersCommitted!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsValidateTotalClustersCommitted(%1!p!,%2!p!): TCC %3!I64x!, TC %4!I64x!, BMSize %5!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_PsGetCurrentThread() Pointer → HexInt64
A12_Vcb->TotalClustersCommitted HexInt64 → HexInt64
A13_Vcb->TotalClusters HexInt64 → HexInt64
A14_Vcb->TPMap.SizeOfBitMap HexInt32 → HexInt32

Event ID 110 — Illegal MDL Complete for major code A10_IrpContext->MajorFunction.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Illegal MDL Complete for major code %1!u!

Fields #

NameDescription
A10_IrpContext->MajorFunction UInt32 → unsignedInt

Event ID 111 — Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Entering: Scb: %1!p!, StartingZero: 0x%2!016I64x!, ByteCount: 0x%3!016I64x!, ExtentsDescriptor: %4!p!, ExtentsDescriptorIndex: %5!d!, ExtentsDescriptorStartOffset: 0x%6!016I64x!, Offset: 0x%7!016I64x!, MaxRuns: %8!d!,

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingZero HexInt64 → HexInt64
A12_ByteCount HexInt64 → HexInt64
A13_ExtentsDescriptor Pointer → HexInt64
A14_*ExtentsDescriptorIndex Int32 → int
A15_*ExtentsDescriptorStartOffset HexInt64 → HexInt64
A16_Offset HexInt64 → HexInt64
A17_MaxRuns Int32 → int

Event ID 112 — RunEntry ==> A10_RunIndex!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

RunEntry ==> %1!4d!: [0x%2!016I64x!, 0x%3!016I64x!], ExtentLength: 0x%4!016I64x!, Offset: 0x%5!016I64x!, RunIndexStartOffset: 0x%6!016I64x!

Fields #

NameDescription
A10_RunIndex Int32 → int
A11_ExtentsDescriptor->Run[RunIndex].BasePage HexInt64 → HexInt64
A12_ExtentsDescriptor->Run[RunIndex].PageCount HexInt64 → HexInt64
A13_ExtentLength HexInt64 → HexInt64
A14_Offset HexInt64 → HexInt64
A15_RunIndexStartOffset HexInt64 → HexInt64

Event ID 113 — Offset is beyond this extent skipping the extent.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Offset is beyond this extent skipping the extent.

Event ID 114 — Shrinking LengthInExtent.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Shrinking LengthInExtent (0x%1!016I64x!) to ByteCount (0x%2!016I64x!) that we have to zero

Fields #

NameDescription
A10_LengthInExtent HexInt64 → HexInt64
A11_ByteCount HexInt64 → HexInt64

Event ID 115 — Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddr.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Zeroing: StartingPhysicalAddr: 0x%1!016I64x!, LengthInExtent: 0x%2!016I64x!

Fields #

NameDescription
A10_StartingPhysicalAddr.QuadPart HexInt64 → HexInt64
A11_LengthInExtent HexInt64 → HexInt64

Event ID 116 — Exiting: ExtentsDescriptorIndex: A10_*ExtentsDescriptorIndex ExtentsDescriptorStartOffset: 0xA11_*ExtentsDescriptorStartOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Exiting: ExtentsDescriptorIndex: %1!d! ExtentsDescriptorStartOffset: 0x%2!016I64x!

Fields #

NameDescription
A10_*ExtentsDescriptorIndex Int32 → int
A11_*ExtentsDescriptorStartOffset HexInt64 → HexInt64

Event ID 117 — Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Entering: Scb: %1!p!, StartingZero: 0x%2!016I64x!, BeyondEndOffset: 0x%3!016I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingOffset HexInt64 → HexInt64
A12_BeyondEndOffset HexInt64 → HexInt64

Event ID 118 — Dsm Ranges[A10_DataSetRangeIndex]: StartingOffset: 0xA11_DsmBuffer->DataSetRanges[DataSetRangeIndex].StartingOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Dsm Ranges[%1!d!]: StartingOffset: 0x%2!016I64x!, LengthInBytes: 0x%3!016I64x!

Fields #

NameDescription
A10_DataSetRangeIndex Int32 → int
A11_DsmBuffer->DataSetRanges[DataSetRangeIndex].StartingOffset HexInt64 → HexInt64
A12_DsmBuffer->DataSetRanges[DataSetRangeIndex].LengthInBytes HexInt64 → HexInt64

Event ID 119 — RemainingClusterCount: 0xA10_RemainingClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

RemainingClusterCount: 0x%1!I64x!, DataSetRangeIndex: %2!d!

Fields #

NameDescription
A10_RemainingClusterCount HexInt64 → HexInt64
A11_DataSetRangeIndex Int32 → int

Event ID 120 — Dsm: TotalNumberOfRanges: A10_DsmByteAddressRanges->TotalNumberOfRanges, NumberOfRangesReturned: A11_DsmByteAddressRanges->NumberOfRangesReturned.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Dsm: TotalNumberOfRanges: %1!d!, NumberOfRangesReturned: %2!d!

Fields #

NameDescription
A10_DsmByteAddressRanges->TotalNumberOfRanges Int32 → int
A11_DsmByteAddressRanges->NumberOfRangesReturned Int32 → int

Event ID 121 — DsmOut Ranges[A10_Index]: StartingAddress: 0xA11_DsmByteAddressRanges->Ranges[Index].StartAddress!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DsmOut Ranges[%1!d!]: StartingAddress: 0x%2!016I64x!, LengthInBytes: 0x%3!016I64x!

Fields #

NameDescription
A10_Index Int32 → int
A11_DsmByteAddressRanges->Ranges[Index].StartAddress HexInt64 → HexInt64
A12_DsmByteAddressRanges->Ranges[Index].LengthInBytes HexInt64 → HexInt64

Event ID 122 — Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddr.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Zeroing: StartingPhysicalAddr: 0x%1!016I64x!, LengthInExtent: 0x%2!016I64x!

Fields #

NameDescription
A10_StartingPhysicalAddr.QuadPart HexInt64 → HexInt64
A11_LengthInExtent HexInt64 → HexInt64

Event ID 123 — Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_*ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_*ExtentsDescriptorStartOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: %1!d!, ExtentsDescriptorStartOffset: 0x%2!016I64x!

Fields #

NameDescription
A10_*ExtentsDescriptorIndex Int32 → int
A11_*ExtentsDescriptorStartOffset HexInt64 → HexInt64

Event ID 124 — Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Entering: Scb: %1!p!, StartingZero: 0x%2!016I64x!, BeyondEndOffset: 0x%3!016I64x!, ByteCount: 0x%4!016I64x!, ExtentsDescriptor: %5!p!, ExtentsDescriptorIndex: %6!d!, ExtentsDescriptorStartOffset: 0x%7!016I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingZero HexInt64 → HexInt64
A12_BeyondEndOffset HexInt64 → HexInt64
A13_ByteCount HexInt64 → HexInt64
A14_ExtentsDescriptor Pointer → HexInt64
A15_ExtentsDescriptorIndex ? *ExtentsDescriptorIndex : 0 Int32 → int
A16_ExtentsDescriptorStartOffset ? *ExtentsDescriptorStartOffset : 0 HexInt64 → HexInt64

Event ID 125 — Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_*ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_*ExtentsDescriptorStartOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: %1!d!, ExtentsDescriptorStartOffset: 0x%2!016I64x!

Fields #

NameDescription
A10_*ExtentsDescriptorIndex Int32 → int
A11_*ExtentsDescriptorStartOffset HexInt64 → HexInt64

Event ID 126 — IrpContext: A10_IrpContext; Scb: A11_Scb; StartOffset: 0xA12_StartOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

IrpContext: %1!p!; Scb: %2!p!; StartOffset: 0x%3!I64x!; ByteCount: 0x%4!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Scb Pointer → HexInt64
A12_StartOffset HexInt64 → HexInt64
A13_ByteCount HexInt32 → HexInt32

Event ID 127 — Return.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Return. IrpContext: %1!p!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64

Event ID 128 — Unexpected open type received: A10_TypeOfOpen.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Unexpected open type received: %1!u!

Fields #

NameDescription
A10_TypeOfOpen UInt32 → unsignedInt

Event ID 129 — Raising STATUS_SUCCESS from NtfsCommonCleanup: A10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Raising STATUS_SUCCESS from NtfsCommonCleanup: %1

Fields #

NameDescription
A10_Status HexInt32 → NTStatus

Event ID 130 — Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Raising STATUS_SUCCESS from NtfsCommonCleanup: 0x%1!X!

Fields #

NameDescription
A10_Status HexInt32 → HexInt32

Event ID 131 — Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Raising STATUS_SUCCESS from NtfsCommonCleanup: 0x%1!X!

Fields #

NameDescription
A10_Status HexInt32 → HexInt32

Event ID 132 — Irp: %1, IC: %2, Vcb: %3, FileObject: %4, RelatedFileObject: %5, FileIdBuffer: %6, Options: 0x%7!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Irp: %1!p!, IC: %2!p!, Vcb: %3!p!, FileObject: %4!p!, RelatedFileObject: %5!p!, FileIdBuffer: %6!S!, Options: 0x%7!08x!, FileAttributes: 0x%8!04x!, DesiredAccess: 0x%9!08x!, ShareAccess: 0x%10!04x!, EaLength: 0x%11!08x!

Event ID 133 — Irp: %1, IC: %2, Vcb: %3, FileObject: %4, RelatedFileObject: %5, Path: %6, Options: 0x%7!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Irp: %1!p!, IC: %2!p!, Vcb: %3!p!, FileObject: %4!p!, RelatedFileObject: %5!p!, Path: %6!S!, Options: 0x%7!08x!, FileAttributes: 0x%8!04x!, DesiredAccess: 0x%9!08x!, ShareAccess: 0x%10!04x!, EaLength: 0x%11!08x!

Event ID 134 — NtfsCommonCreate: Volume is locked or we have performed a dismount.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonCreate: Volume is locked or we have performed a dismount. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Vcb State: %5!x!.

Event ID 135 — NtfsCommonVolumeOpen: Invalid create disposition for volume open.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonVolumeOpen: Invalid create disposition for volume open. Thread: %1!p!, CreateDisposition: 0x%2!x!.

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64
A11_CreateDisposition HexInt32 → HexInt32

Event ID 136 — NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Vcb State: 0x%5!08x!.

Event ID 137 — NtfsCommonVolumeOpen: Thread: %1, Vcb: %2, VolumeName: %3, VolumeLabel: %4, Requested ShareAccess: 0x%5!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonVolumeOpen: Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Requested ShareAccess: 0x%5!08x!, Vcb->CleanupCount: %6!d!, BiasedCleanupCount: %7!d!.

Event ID 138 — NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Vcb State: 0x%5!08x!.

Event ID 139 — NtfsCommonVolumeOpen: Conlicting file objects.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonVolumeOpen: Conlicting file objects. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Requested ShareAccess: 0x%5!08x!, Vcb->ReadOnlyCloseCount: %6!d!, Vcb->CloseCount: %7!d!, Vcb->SystemFileCloseCount: %8!d!.

Event ID 140 — NtfsHandlePagingFile: Paging file already open, paging files can only be opened once.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsHandlePagingFile: Paging file already open, paging files can only be opened once. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Fcb->CleanupCount: %7!d!, Fcb->FcbState: 0x%8!08x!, IrpSp->Flags: 0x%9!08x!.

Event ID 141 — NtfsHandlePagingFile: Cannot open system file as paging file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsHandlePagingFile: Cannot open system file as paging file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Fcb->FcbState: 0x%7!08x!, IrpSp->Flags: 0x%8!08x!.

Event ID 142 — NtfsHandlePagingFile: Persisted paging file already exists.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsHandlePagingFile: Persisted paging file already exists. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, IrpContext->State: 0x%7!08x!, IrpSp->Flags: 0x%8!08x!.

Event ID 143 — NtfsOpenFcbById: Invalid system file access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenFcbById: Invalid system file access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, CreateDisposition: 0x%8!08x!, DesiredAccess: 0x%9!08x!.

Event ID 144 — NtfsOpenExistingPrefixFcb: Can not directly open txf directory.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenExistingPrefixFcb: Can not directly open txf directory. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileAttributes: 0x%7!08x!, Rmstate: 0x%8!08x!.

Event ID 145 — NtfsOpenExistingPrefixFcb: Invalid system file access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenExistingPrefixFcb: Invalid system file access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, CreateDisposition: 0x%8!08x!, DesiredAccess: 0x%9!08x!.

Event ID 146 — NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!.

Event ID 147 — NtfsOpenFile: Invalid system file access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenFile: Invalid system file access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, CreateDisposition: 0x%8!08x!, DesiredAccess: 0x%9!08x!.

Event ID 148 — NtfsOpenFile: Deny open when txf rm is active.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenFile: Deny open when txf rm is active. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, TxfRmcb Rmstate: 0x%7!08x!.

Event ID 149 — NtfsCreateNewFile: Deny creation in system directory (except root).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCreateNewFile: Deny creation in system directory (except root). Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, (Parent Fcb): Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, TxfRmcb state: 0x%8!08x!, AttrTypeCode: 0x%9!x!.

Event ID 150 — NtfsCreateNewFile: Unable to create Ea for the file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCreateNewFile: Unable to create Ea for the file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Create options: 0x%7!08x!, Ccb flags: 0x%8!08x!.

Event ID 151 — NtfsCreateNewFile: Unable to create in the $txf directory.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCreateNewFile: Unable to create in the $txf directory. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, (Parent Fcb) Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, TxfRmcb state: 0x%8!08x!.

Event ID 152 — NtfsOpenSubdirectory: Denying access to $Txf file when the RM is active.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenSubdirectory: Denying access to $Txf file when the RM is active. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, TxfRmcb state: 0x%7!08x!.

Event ID 153 — NtfsOpenAttributeInExistingFile: Denying access due to caller being Ea blind.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttributeInExistingFile: Denying access due to caller being Ea blind. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, NeedEaCount: %7!d!, CreateOptions: 0x%8!08x!, CcbFlags: 0x%9!08x!.

Event ID 154 — NtfsOpenAttributeInExistingFile: Fail to find $INDEX_ROOT attribute.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttributeInExistingFile: Fail to find $INDEX_ROOT attribute. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, AttrTypeCode to create: 0x%7!x!, CreateDisposition: 0x%8!08x!.

Event ID 155 — NtfsOpenAttributeInExistingFile: Denying access for volume root directory.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttributeInExistingFile: Denying access for volume root directory. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, CreateDisposition: 0x%7!08x!.

Event ID 156 — NtfsCreateNewFile: Not allowed to create streams on system files.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCreateNewFile: Not allowed to create streams on system files. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, AttrTypeCode: 0x%8!x!.

Event ID 157 — NtfsOverwriteAttr: Cannot overwrite hidden or system attribute for a non-paging file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOverwriteAttr: Cannot overwrite hidden or system attribute for a non-paging file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, DuplicateInfo attributes: 0x%7!08x!, FileAttributes: 0x%8!08x!.

Event ID 158 — NtfsOverwriteAttr: Denying access due to user being Ea blind.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOverwriteAttr: Denying access due to user being Ea blind. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Create options: 0x%7!08x!.

Event ID 159 — NtfsOverwriteAttr: Deny access due to encryption happening on the stream.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOverwriteAttr: Deny access due to encryption happening on the stream. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, AttributeTypeCode: 0x%7!x!, Scb state: 0x%8!08x!, Scb HighWaterMark: %9!I64d!.

Event ID 160 — NtfsCheckValidAttributeAccess: Supersede or overwrite is not allowed on this type of named attribute.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckValidAttributeAccess: Supersede or overwrite is not allowed on this type of named attribute. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, AttributeTypeCode: 0x%5!x!, CreateDisposition: 0x%6!08x!.

Event ID 161 — NtfsCheckValidAttributeAccess: Only read attributes access is supported on this attribute.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckValidAttributeAccess: Only read attributes access is supported on this attribute. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, AttributeTypeCode: 0x%5!x!, DesiredAccess: 0x%6!08x!.

Event ID 162 — NtfsCheckValidAttributeAccess: Deny access for protected system attributes.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckValidAttributeAccess: Deny access for protected system attributes. Thread: %1!p!, AttributeTypeCode: %2!x!.

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64
A11_*AttrCode HexInt32 → HexInt32

Event ID 163 — NtfsOpenAttributeCheck: File already has user writable references.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttributeCheck: File already has user writable references. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Requested ShareAccess: 0x%10!08x!, Previously granted access: 0x%11!08x!.

Event ID 164 — NtfsOpenAttributeCheck: Deny access for online encryption backup data stream.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttributeCheck: Deny access for online encryption backup data stream. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, AttributeTypeCode: 0x%8!x!, Attribute Name: %9!S!.

Event ID 165 — NtfsOpenAttributeCheck: File was granted write access but has image section.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttributeCheck: File was granted write access but has image section. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Previously granted access: 0x%10!08x!.

Event ID 166 — NtfsOpenAttribute: Denying write access on disallowed writes.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttribute: Denying write access on disallowed writes. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Disallow write count: %8!d!, Desired Access: 0x%9!08x!.

Event ID 167 — NtfsOpenAttribute: File already has user writable references.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttribute: File already has user writable references. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Requested ShareAccess: 0x%10!08x!, Previously granted access: 0x%11!08x!.

Event ID 168 — NtfsOpenAttribute: Open for exclusive read access is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttribute: Open for exclusive read access is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Requested share access: 0x%7!08x!, FO flags: 0x%8!08x!.

Event ID 169 — NtfsOpenAttribute: File already has user writable references.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttribute: File already has user writable references. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Requested ShareAccess: 0x%10!08x!, Previously granted access: 0x%11!08x!.

Event ID 170 — NtfsOpenAttribute: Open for exclusive read access is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenAttribute: Open for exclusive read access is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Requested share access: 0x%7!08x!, FO flags: 0x%8!08x!.

Event ID 171 — NtfsCheckExistingFile: Desired access conflicts with read-only state.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckExistingFile: Desired access conflicts with read-only state. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Desired Access: 0x%7!08x!, FileAttributes: 0x%8!08x!, SL control flags: 0x%9!08x!.

Event ID 172 — NtfsOpenExistingEncryptedStream: No encryption driver found.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenExistingEncryptedStream: No encryption driver found. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileAttributes: 0x%7!08x!, NtfsData flags: 0x%8!08x!.

Event ID 173 — NtfsOpenExistingEncryptedStream: Opening for read/write access not allowed on compressed file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsOpenExistingEncryptedStream: Opening for read/write access not allowed on compressed file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileAttributes: 0x%7!08x!, Stream attribute flags: 0x%8!08x!.

Event ID 174 — NtfsEncryptionCreateCallback: Encrytion engine fail to encrypt all streams for file with open handle.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEncryptionCreateCallback: Encrytion engine fail to encrypt all streams for file with open handle. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Fcb cleanup count: %7!d!, EncryptionCallBackTable flags: 0x%8!08x!.

Event ID 175 — NtfsFindStartingNode: Opening not allowed for txf name when RM is active.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFindStartingNode: Opening not allowed for txf name when RM is active. Thread: %1!p!, Fcb: %2!p!, FileRef: 0x%3!I64x!, TxfRmcb RM state: %4!x!.

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64
A11_CurrentFcb Pointer → HexInt64
A12_NtfsFullFileRefNumber( _CurrentFcb->FileReference ) HexInt64 → HexInt64
A13_CurrentFcb->TxfRmcb->RmState HexInt32 → HexInt32

Event ID 176 — NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Link Name: %7!S!, DesiredAccess: 0x%8!08x!, DesiredShareAccess: 0x%9!08x!, IoShareAccessFlags: 0x%10!08x!, LinkShareAccess->OpenCount: %11!d!, LinkShareAccess->Deleters: %12!d!, LinkShareAccess->SharedDelete: %13!d!.

Event ID 177 — NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb Type Code: 0x%7!x!, Scb Name: %8!S!, DesiredAccess: 0x%9!08x!, DesiredShareAccess: 0x%10!08x!, IoShareAccessFlags: 0x%11!08x!, ShareAccess->OpenCount: %12!d!, ShareAccess->Readers: %13!d!, ShareAccess->Writers: %14!d!, ShareAccess->->Deleters: %15!d!, ShareAccess->SharedRead: %16!d!, ShareAccess->SharedWrite: %17!d!, ShareAccess->SharedDelete: %18!d!.

Event ID 178 — NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb Type Code: 0x%7!x!, Scb Name: %8!S!, Link Name: %9!S!, DesiredAccess: 0x%10!08x!, DesiredShareAccess: 0x%11!08x!, IoShareAccessFlags: 0x%12!08x!, ShareAccess->OpenCount: %13!d!, ShareAccess->Readers: %14!d!, ShareAccess->Writers: %15!d!, ShareAccess->->Deleters: %16!d!, ShareAccess->SharedRead: %17!d!, ShareAccess->SharedWrite: %18!d!, ShareAccess->SharedDelete: %19!d!, LinkShareAccess->OpenCount: %20!d!, LinkShareAccess->Deleters: %21!d!, LinkShareAccess->SharedDelete: %22!d!.

Event ID 179 — NtfsReCheckShareAccess: Does not meet allow open requirement.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsReCheckShareAccess: Does not meet allow open requirement. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb Type Code: 0x%7!x!, Scb Name: %8!S!, Link Name: %9!S!, Previously granted access: 0x%10!08x!, AccessState->Flags: 0x%11!08x!, DesiredShareAccess: 0x%12!08x!, CreateDisposition: 0x%13!08x!, OpenCount: %14!d!, Readers: %15!d!, Writers: %16!d!, Deleters: %17!d!, SharedRead: %18!d!, Lcb Deleters: %19!d!.

Event ID 180 — %1:%2 Status: %3 ProcessName: %4.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1:%2!d! Status: %3!S! ProcessName: %4!S!

Event ID 181 — %1:%2 Status: %3 ProcessName: %4.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1:%2!d! Status: %3!S! ProcessName: %4!S!

Event ID 182 — %1:%2 Status: %3 ProcessName: %4.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1:%2!d! Status: %3!S! ProcessName: %4!S!

Event ID 183 — %1:%2 Status: %3 ProcessName: %4.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1:%2!d! Status: %3!S! ProcessName: %4!S!

Event ID 184 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Will tell storage we are freeing at A11_StartingCluster!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSendUnusedClustersHint: Vcb %1!p! - Will tell storage we are freeing at %2!I64x! for %3!x! clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_StartingCluster HexInt64 → HexInt64
A12_RunLength HexInt32 → HexInt32

Event ID 185 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Flush requested.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSendUnusedClustersHint: Vcb %1!p! - Flush requested

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 186 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Created new MarkUnusedContext A11_*MarkUnusedContext, DEALLOCATED_CLUSTERS A12_(*MarkUnusedContext)->DeallocatedClusters, MCB A13__(*MarkUnusedContext)->De...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSendUnusedClustersHint: Vcb %1!p! -  Created new MarkUnusedContext %2!p!, DEALLOCATED_CLUSTERS %3!p!, MCB %4!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_*MarkUnusedContext Pointer → HexInt64
A12_(*MarkUnusedContext)->DeallocatedClusters Pointer → HexInt64
A13__(*MarkUnusedContext)->DeallocatedClusters->Mcb Pointer → HexInt64

Event ID 187 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Successfully added clusters starting at A11_StartingCluster!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSendUnusedClustersHint: Vcb %1!p! - Successfully added clusters starting at %2!I64x! for %3!x! into MCB %4!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_StartingCluster HexInt64 → HexInt64
A12_RunLength HexInt32 → HexInt32
A13__(*MarkUnusedContext)->DeallocatedClusters->Mcb Pointer → HexInt64

Event ID 188 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - MCB A11__(*MarkUnusedContext)->DeallocatedClusters->Mcb is full.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSendUnusedClustersHint: Vcb %1!p! - MCB %2!p! is full

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11__(*MarkUnusedContext)->DeallocatedClusters->Mcb Pointer → HexInt64

Event ID 189 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Queuing request to IC pre-trim list, MUC A11_*MarkUnusedContext, IC A12_IrpContext.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSendUnusedClustersHint: Vcb %1!p! - Queuing request to IC pre-trim list, MUC %2!p!, IC %3!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_*MarkUnusedContext Pointer → HexInt64
A12_IrpContext Pointer → HexInt64

Event ID 190 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Failed to allocate/initial MarkUnusedContext.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSendUnusedClustersHint: Vcb %1!p! -  Failed to allocate/initial MarkUnusedContext

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 191 — NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt A12_Src->ClustersCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsTransferMaxDataSetRanges: Src %1!p!, Dst %2!p!, SrcRemainClusCt %3!I64x!, SrcOrigClusCt %4!I64x!, SrcDSRL %5!x! - Entering

Fields #

NameDescription
A10_Src Pointer → HexInt64
A11_Dst Pointer → HexInt64
A12_Src->ClustersCount HexInt64 → HexInt64
A13_Src->DeallocatedClusters->ClusterCount HexInt64 → HexInt64
A14_SrcDsmAttr->DataSetRangesLength HexInt32 → HexInt32

Event ID 192 — NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt A12_Src->ClustersCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsTransferMaxDataSetRanges: Src %1!p!, Dst %2!p!, SrcRemainClusCt %3!I64x!, DstClusCt %4!I64x!, DstDSRL %5!x!, DstLIB %6!I64x!, DstSOff %7!I64x! - Leaving

Fields #

NameDescription
A10_Src Pointer → HexInt64
A11_Dst Pointer → HexInt64
A12_Src->ClustersCount HexInt64 → HexInt64
A13_Dst->ClustersCount HexInt64 → HexInt64
A14_DstDsmAttr->DataSetRangesLength HexInt32 → HexInt32
A15_DstFirstDataSetRangePtr->LengthInBytes HexInt64 → HexInt64
A16_DstFirstDataSetRangePtr->StartingOffset HexInt64 → HexInt64

Event ID 193 — NtfsMarkUnusedContextPostTrimProcessing: Entering.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPostTrimProcessing: Entering

Event ID 194 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DC A12_Vcb->DeallocatedClusters!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPostTrimProcessing: Vcb %1!p!, MUC %2!p! - DC %3!I64x!, DCIT %4!x!, DCTD %5!x!, CC %6!I64x!, IR %7!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_Vcb->DeallocatedClusters HexInt64 → HexInt64
A13_Vcb->DeallocatedClustersListLengthInTrim HexInt32 → HexInt32
A14_Vcb->DeallocatedClustersListLengthToDrain HexInt32 → HexInt32
A15_Clusters->ClusterCount HexInt64 → HexInt64
A16_InitialRanges HexInt32 → HexInt32

Event ID 195 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - Removed interior slab(s) from TP map - [LCN A12_StartingLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPostTrimProcessing: Vcb %1!p!, MUC %2!p! - Removed interior slab(s) from TP map - [LCN %3!I64X!, len %4!I64X!] => [LCN %5!I64X!, len %6!I64X!], [LCN %7!I64X!, len %8!I64X!]

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_StartingLcn HexInt64 → HexInt64
A13_ClusterCount HexInt64 → HexInt64
A14_FreeClusterBase1 HexInt64 → HexInt64
A15_FreeClusterCount1 HexInt64 → HexInt64
A16_FreeClusterBase2 HexInt64 → HexInt64
A17_FreeClusterCount2 HexInt64 → HexInt64

Event ID 196 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - Releasing bitmap.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPostTrimProcessing: Vcb %1!p! - Releasing bitmap

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 197 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - CloseCount A11_Vcb->CloseCount.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPostTrimProcessing: Vcb %1!p! - CloseCount %2!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->CloseCount HexInt32 → HexInt32

Event ID 198 — NtfsMarkUnusedContextPostTrimProcessing: Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPostTrimProcessing: Leaving

Event ID 199 — NtfsAsyncSendUnusedClustersHintCompletionRoutine: Irp A10_Irp.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAsyncSendUnusedClustersHintCompletionRoutine: Irp %1!p!

Fields #

NameDescription
A10_Irp Pointer → HexInt64

Event ID 200 — NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb, IC A11_IrpContext - Entering.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimProcessing: Vcb %1!p!, IC %2!p! - Entering

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64

Event ID 201 — NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Kicked off DelayedWorkQueue.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimProcessing: Vcb %1!p! - Kicked off DelayedWorkQueue

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 202 — NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimProcessing: Vcb %1!p! - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 203 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Entering Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Entering Vcb %1!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 204 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Small MUC A11_SmallMarkUnusedContext instead of MUC A12_MarkUnusedContext.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p! - Small MUC %2!p! instead of MUC %3!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_SmallMarkUnusedContext Pointer → HexInt64
A12_MarkUnusedContext Pointer → HexInt64

Event ID 205 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Failed to allocate small MUC so use MUC A11_MarkUnusedContext.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p! - Failed to allocate small MUC so use MUC %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64

Event ID 206 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage ioctl down.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p! - Sending storage ioctl down.  MUC %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64

Event ID 207 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - [A12_TrimEntryCount++] Offset A13_DataSetRangePtr->StartingOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p!, MUC %2!p! - [%3!x!] Offset %4!I64x!, Length %5!I64x! - trim entry

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_TrimEntryCount++ HexInt32 → HexInt32
A13_DataSetRangePtr->StartingOffset HexInt64 → HexInt64
A14_DataSetRangePtr->LengthInBytes HexInt64 → HexInt64

Event ID 208 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext, Irp A12_IrpUsed - Completed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p!, MUC %2!p!, Irp %3!p! - Completed

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_IrpUsed Pointer → HexInt64

Event ID 209 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - A12_Status - failed to send.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p!, MUC %2!p! - %3!x! - failed to send

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_Status HexInt32 → HexInt32

Event ID 210 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Add MUC A11_MarkUnusedContext to post trim list.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p! - Add MUC %2!p! to post trim list

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64

Event ID 211 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Free small MUC A11_MarkUnusedContext.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p! - Free small MUC %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64

Event ID 212 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage ioctl down failed with A11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb %1!p! - Sending storage ioctl down failed with %2!x!.  MUC %3!p!, Count %4!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Status HexInt32 → HexInt32
A12_MarkUnusedContext Pointer → HexInt64
A13_((MarkUnusedContext != NULL) __ (MarkUnusedContext->DeallocatedClusters != NULL)) ? MarkUnusedContext->DeallocatedClusters->ClusterCount : -1LL HexInt64 → HexInt64

Event ID 213 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkUnusedContextPreTrimWorkItemProcessing: Leaving

Event ID 214 — NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - There are waiters for DC A11_DeallocatedClusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWakeupDeallocatedClustersWaiters: Vcb %1!p! - There are waiters for DC %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_DeallocatedClusters Pointer → HexInt64

Event ID 215 — NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Waking up waiter for DC A11_DeallocatedClusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWakeupDeallocatedClustersWaiters: Vcb %1!p! - Waking up waiter for DC %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_DeallocatedClusters Pointer → HexInt64

Event ID 216 — NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Done waking up DC A11_DeallocatedClusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWakeupDeallocatedClustersWaiters: Vcb %1!p! - Done waking up DC %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_DeallocatedClusters Pointer → HexInt64

Event ID 217 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb, All A11_All - Entering.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWaitForDeallocatedClustersToDrain: Vcb %1!p!, All %2!x! - Entering

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_All HexInt32 → HexInt32

Event ID 218 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting to drain.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWaitForDeallocatedClustersToDrain: Vcb %1!p! - Waiting to drain

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 219 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting for partial drain.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWaitForDeallocatedClustersToDrain: Vcb %1!p! - Waiting for partial drain

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 220 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWaitForDeallocatedClustersToDrain: Vcb %1!p! - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 221 — NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Entering.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb %1!p! - Entering

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 222 — NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Inserted A11_DeallocatedClustersToWaitFor->DeallocatedClusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb %1!p! - Inserted %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_DeallocatedClustersToWaitFor->DeallocatedClusters Pointer → HexInt64

Event ID 223 — NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb %1!p! - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 224 — NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Vcb A10_IrpContext->Vcb - Wait for DC A11_DeallocatedClustersToWaitFor->DeallocatedClusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Vcb %1!p! - Wait for DC %2!p!

Fields #

NameDescription
A10_IrpContext->Vcb Pointer → HexInt64
A11_DeallocatedClustersToWaitFor->DeallocatedClusters Pointer → HexInt64

Event ID 225 — NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds (s), Exceeded by A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? ...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for %1!d! (s), Exceeded by %2!d! (s), IC %3!p!, Vcb %4!p!, DC %5!p!

Fields #

NameDescription
A10_WaitInSeconds Int32 → int
A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? (ULONG)(((CurrentTime.QuadPart - DeallocatedClustersToWaitFor->EndTime.QuadPart) * NtfsData.SystemTimeIncrement)/INTERVAL_ONE_SECOND) : 0) Int32 → int
A12_IrpContext Pointer → HexInt64
A13_IrpContext->Vcb Pointer → HexInt64
A14_DeallocatedClusters Pointer → HexInt64

Event ID 226 — NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds (s), Exceeded by A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? ...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for %1!d! (s), Exceeded by %2!d! (s), IC %3!p!, Vcb %4!p!, DC %5!p!

Fields #

NameDescription
A10_WaitInSeconds Int32 → int
A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? (ULONG)(((CurrentTime.QuadPart - DeallocatedClustersToWaitFor->EndTime.QuadPart) * NtfsData.SystemTimeIncrement)/INTERVAL_ONE_SECOND) : 0) Int32 → int
A12_IrpContext Pointer → HexInt64
A13_IrpContext->Vcb Pointer → HexInt64
A14_DeallocatedClusters Pointer → HexInt64

Event ID 227 — NtfsCheckForTrimThrottling: Vcb A10_Vcb - hitting trim threshold A11_Vcb->DeallocatedClustersListLengthInTrim.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckForTrimThrottling: Vcb %1!p! - hitting trim threshold %2!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->DeallocatedClustersListLengthInTrim Int32 → int

Event ID 228 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Entering.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - Entering

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 229 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - Precondition checks failed

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 230 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed; AcquiredSyncResource A11_AcquiredVcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - Precondition checks failed; AcquiredSyncResource %2!u!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_AcquiredVcb UInt32 → unsignedInt

Event ID 231 — NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - Skipping deallocated clusters gen'd by smart trim.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p!, MUC %2!p! - Skipping deallocated clusters gen'd by smart trim

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64

Event ID 232 — NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - MCB run A12_RunIndex; offs 0xA13_StartingOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p!, MUC %2!p! - MCB run %3!u!; offs 0x%4!I64X!, len 0x%5!I64X!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_RunIndex UInt32 → unsignedInt
A13_StartingOffset HexInt64 → HexInt64
A14_LengthInBytes HexInt64 → HexInt64

Event ID 233 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - MUC A11_MarkUnusedContext, DSR count A12_DataSetRangeCount, MCB count A13_McbRunCount, ST free slots A14_SmartTrimFreeRangeCount.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - MUC %2!p!, DSR count %3!u!, MCB count %4!u!, ST free slots %5!u!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_DataSetRangeCount UInt32 → unsignedInt
A13_McbRunCount UInt32 → unsignedInt
A14_SmartTrimFreeRangeCount UInt32 → unsignedInt

Event ID 234 — NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DSR range A12_RunIndex; offs 0xA13_DataSetRange->StartingOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p!, MUC %2!p! - DSR range %3!u!; offs 0x%4!I64X!, len 0x%5!I64X!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64
A12_RunIndex UInt32 → unsignedInt
A13_DataSetRange->StartingOffset HexInt64 → HexInt64
A14_DataSetRange->LengthInBytes HexInt64 → HexInt64

Event ID 235 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - MCB lcn A11_StartingLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - MCB lcn %2!I64X! len %3!I64X! maps to TP map bits [0x%4!X!, 0x%5!X!]

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_StartingLcn HexInt64 → HexInt64
A12_ClusterCount HexInt64 → HexInt64
A13_FirstTpMapBit HexInt32 → HexInt32
A14_LastTpMapBit HexInt32 → HexInt32

Event ID 236 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Smart trim state on exit; A11_SmartTrimState->SlabRangesCount ranges.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - Smart trim state on exit; %2!u! ranges:

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_SmartTrimState->SlabRangesCount UInt32 → unsignedInt

Event ID 237 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Range A11_SlabRangeIndex: FirstTPMapBit 0xA12_SlabRange->FirstTPMapBit, LastTPMapBit 0xA13_SlabRange->LastTPMapBit.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - Range %2!u!: FirstTPMapBit 0x%3!X!, LastTPMapBit 0x%4!X!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_SlabRangeIndex UInt32 → unsignedInt
A12_SlabRange->FirstTPMapBit HexInt32 → HexInt32
A13_SlabRange->LastTPMapBit HexInt32 → HexInt32

Event ID 238 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpdateSmartTrimState: Vcb %1!p! - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 239 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Entering.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEvalSmartTrimState: Vcb %1!p! - Entering

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 240 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEvalSmartTrimState: Vcb %1!p! - Precondition checks failed

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 241 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed; AcquiredBitmap A11_AcquiredBitmap.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEvalSmartTrimState: Vcb %1!p! - Precondition checks failed; AcquiredBitmap %2!u!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_AcquiredBitmap UInt32 → unsignedInt

Event ID 242 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Checking slab 0xA11_TpMapBit for allocations.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEvalSmartTrimState: Vcb %1!p! - Checking slab 0x%2!X! for allocations

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_TpMapBit HexInt32 → HexInt32

Event ID 243 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Slab 0xA11_TpMapBit has allocations, will not trim.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEvalSmartTrimState: Vcb %1!p! - Slab 0x%2!X! has allocations, will not trim

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_TpMapBit HexInt32 → HexInt32

Event ID 244 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Free slab found - TP map bit 0xA11_TpMapBit, lcn A12_SlabBaseLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEvalSmartTrimState: Vcb %1!p! - Free slab found - TP map bit 0x%2!X!, lcn %3!I64X!, len %4!I64X!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_TpMapBit HexInt32 → HexInt32
A12_SlabBaseLcn HexInt64 → HexInt64
A13_SlabLengthInClusters HexInt64 → HexInt64

Event ID 245 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEvalSmartTrimState: Vcb %1!p! - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 246 — NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, VcbState: 0x%5!08x!, SL control flags: 0x%6!08x!.

Event ID 247 — NtfsVolumeDasdIo: Data section blocking flush.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsVolumeDasdIo: Data section blocking flush. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Flush status: %5!S!.

Event ID 248 — Could not find paging file run.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Could not find paging file run.

Event ID 249 — Could not find paging file MCB entry.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Could not find paging file MCB entry.

Event ID 250 — Could not find paging file run.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Could not find paging file run.

Event ID 251 — Writing to $Bitmap.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Writing to $Bitmap. Vcb: %1!p!, Offset: 0x%2!I64x!, Length: 0x%3!x!

Fields #

NameDescription
A10_Scb->Vcb Pointer → HexInt64
A11_StartingVbo HexInt64 → HexInt64
A12_ByteCount HexInt32 → HexInt32

Event ID 252 — NTFS: Posting hotfix on file object: A10_FileObject.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NTFS: Posting hotfix on file object: %1!p!

Fields #

NameDescription
A10_FileObject Pointer → HexInt64

Event ID 253 — NTFS: Freeing Bad Vcn: A10_((ULONG)BadVcn)!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NTFS:     Freeing Bad Vcn: %1!08x!, %2!08x!

Fields #

NameDescription
A10_((ULONG)BadVcn) HexInt32 → HexInt32
A11_((PLARGE_INTEGER)_BadVcn)->HighPart HexInt32 → HexInt32

Event ID 254 — NTFS: Retiring Bad Lcn: A10_((ULONG)BadLcn)!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NTFS:     Retiring Bad Lcn: %1!08x!, %2!08x!

Fields #

NameDescription
A10_((ULONG)BadLcn) HexInt32 → HexInt32
A11_((PLARGE_INTEGER)_BadLcn)->HighPart HexInt32 → HexInt32

Event ID 255 — NTFS: Reallocating Bad Vcn.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NTFS:     Reallocating Bad Vcn

Event ID 256 — NTFS: Bad Cluster replaced.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NTFS:     Bad Cluster replaced

Event ID 257 — IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

IrpContext: %1!p!; Vcb: %2!p!; NewBufferSize: 0x%3!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_NewBufferSize HexInt32 → HexInt32

Event ID 258 — Compression buffers are already big enough.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Compression buffers are already big enough. NewBufferSize: 0x%1!08x!, ExistingBufferSize: 0x%2!08x!

Fields #

NameDescription
A10_NewBufferSize HexInt32 → HexInt32
A11_NtfsGetCompressionBufferSize() HexInt32 → HexInt32

Event ID 259 — A10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1

Fields #

NameDescription
A10_Status HexInt32 → NTStatus

Event ID 260 — IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

IrpContext: %1!p!; Vcb: %2!p!; NewBufferSize: 0x%3!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_NewBufferSize HexInt32 → HexInt32

Event ID 261 — Compression buffers are already big enough.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Compression buffers are already big enough. NewBufferSize: 0x%1!08x!, ExistingBufferSize: 0x%2!08x!

Fields #

NameDescription
A10_NewBufferSize HexInt32 → HexInt32
A11_NtfsGetUsaBufferSize( Vcb ) HexInt32 → HexInt32

Event ID 262 — A10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1

Fields #

NameDescription
A10_Status HexInt32 → NTStatus

Event ID 263 — NtfsDefragFileInternal: Defrag is denied.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal: Defrag is denied. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Persist flags: 0x%10!08x!, Ccb flags: 0x%11!08x!.

Event ID 264 — NtfsDefragFileInternal: Vcb A10_Vcb - Calling FRD.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal: Vcb %1!p! - Calling FRD

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 265 — NtfsDefragFileInternal: Vcb A10_Vcb - Done calling FRD.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal: Vcb %1!p! - Done calling FRD

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 266 — NtfsDefragFileInternal: Defrag is denied.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal: Defrag is denied. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Persist flags: 0x%10!08x!, Ccb flags: 0x%11!08x!.

Event ID 267 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal(%1!p!,%2!p!): Scb %3!p!, FRef %4!I64x!, Vcn %5!I64x!, CC %6!I64x!, CurrLcn %7!I64x!, NewLcn %8!I64x!, Len %9!x!, DA %10!d!, Status %11!x! - copy offload

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64
A14_MoveData->StartingVcn.QuadPart HexInt64 → HexInt64
A15_TransferClusters HexInt64 → HexInt64
A16_Lcn HexInt64 → HexInt64
A17_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64
A18_CopyLength HexInt32 → HexInt32
A19_Flags.UseDelayedAllocation Int32 → int
A20_Status HexInt32 → HexInt32

Event ID 268 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal(%1!p!,%2!p!): Scb %3!p!, FRef %4!I64x!, Vcn %5!I64x!, CC %6!I64x!, CurrLcn %7!I64x!, NewLcn %8!I64x!, Len %9!x!, DA %10!d!, Status %11!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64
A14_MoveData->StartingVcn.QuadPart HexInt64 → HexInt64
A15_TransferClusters HexInt64 → HexInt64
A16_Lcn HexInt64 → HexInt64
A17_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64
A18_CopyLength HexInt32 → HexInt32
A19_Flags.UseDelayedAllocation Int32 → int
A20_MyStatus HexInt32 → HexInt32

Event ID 269 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal(%1!p!,%2!p!): Scb %3!p!, FRef %4!I64x!, CurrLcn %5!I64x!, Len %6!x!, Status %7!x! - read completed

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64
A14_Lcn HexInt64 → HexInt64
A15_CopyLength HexInt32 → HexInt32
A16_MyStatus HexInt32 → HexInt32

Event ID 270 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal(%1!p!,%2!p!): Scb %3!p!, FRef %4!I64x!, NewLcn %5!I64x!, Len %6!x!, Status %7!x! - write completed

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64
A14_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64
A15_CopyLength HexInt32 → HexInt32
A16_MyStatus HexInt32 → HexInt32

Event ID 271 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal(%1!p!,%2!p!): Scb %3!p!, FRef %4!I64x!, Vcn %5!I64x!, CC %6!I64x!, CurrLcn %7!I64x!, NewLcn %8!I64x!, DA %9!d!, ValidClusters %10!I64x! - beyond VDL

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64
A14_MoveData->StartingVcn.QuadPart HexInt64 → HexInt64
A15_TransferClusters HexInt64 → HexInt64
A16_Lcn HexInt64 → HexInt64
A17_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64
A18_Flags.UseDelayedAllocation Int32 → int
A19_ValidClusters HexInt64 → HexInt64

Event ID 272 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFileInternal(%1!p!,%2!p!): Scb %3!p!, FRef %4!I64x!, Vcn %5!I64x!, CC %6!I64x! - committed

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64
A14_MoveData->StartingVcn.QuadPart HexInt64 → HexInt64
A15_TransferClusters HexInt64 → HexInt64

Event ID 273 — NtfsDefragFile: Defrag is denied without manage volume access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefragFile: Defrag is denied without manage volume access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb flags: 0x%7!08x!.

Event ID 274 — NtfsEncryptDecryptOnline: Defrag is denied.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEncryptDecryptOnline: Defrag is denied. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Persist flags: 0x%10!08x!, Ccb flags: 0x%11!08x!.

Event ID 275 — NtfsEncryptDecryptOnline: Vcb A10_Vcb - Calling FRD.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEncryptDecryptOnline: Vcb %1!p! - Calling FRD

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 276 — NtfsEncryptDecryptOnline: Vcb A10_Vcb - Done calling FRD.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEncryptDecryptOnline: Vcb %1!p! - Done calling FRD

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 277 — NtfsEncryptDecryptOnline: Defrag is denied.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEncryptDecryptOnline: Defrag is denied. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Persist flags: 0x%10!08x!, Ccb flags: 0x%11!08x!.

Event ID 278 — SCB: A10_Scb, VDL=0xA11_Scb->Header.ValidDataLength.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

SCB: %1!p!, VDL=0x%2!I64x!, FS=0x%3!I64x!, StartOff=0x%4!I64x!, StartVcn=0x%5!I64x!, Length=0x%6!I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Scb->Header.ValidDataLength.QuadPart HexInt64 → HexInt64
A12_Scb->Header.FileSize.QuadPart HexInt64 → HexInt64
A13_QueryDaxExtents->FileOffset HexInt64 → HexInt64
A14_StartingVcn HexInt64 → HexInt64
A15_QueryDaxExtents->Length HexInt64 → HexInt64

Event ID 279 — StartOff=0xA10_QueryDaxExtents->FileOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

StartOff=0x%1!I64x!, Length=0x%2!I64x!, EffectiveLength=0x%3!I64x! StartVcn=0x%4!I64x!, BeyondEndVcn=0x%5!I64x!, Clusters=0x%6!I64x!, LastVcnInFile=0x%7!I64x!

Fields #

NameDescription
A10_QueryDaxExtents->FileOffset HexInt64 → HexInt64
A11_QueryDaxExtents->Length HexInt64 → HexInt64
A12_EffectiveInputFileRegionLength HexInt64 → HexInt64
A13_StartingVcn HexInt64 → HexInt64
A14_BeyondEndVcn HexInt64 → HexInt64
A15_RemainingClusterCount HexInt64 → HexInt64
A16_LastVcnInFile HexInt64 → HexInt64

Event ID 280 — NumberOfValidRuns: 0.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NumberOfValidRuns: 0

Event ID 281 — RemainingClusterCount: 0xA10_RemainingClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

RemainingClusterCount: 0x%1!I64x!, DataSetRangeIndex: %2!d!, OutputBufferLength: 0x%3!d!

Fields #

NameDescription
A10_RemainingClusterCount HexInt64 → HexInt64
A11_DataSetRangeIndex Int32 → int
A12_OutputBufferLength Int32 → int

Event ID 282 — STATUS_BUFFER_TOO_SMALL from FsLib.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

STATUS_BUFFER_TOO_SMALL from FsLib. NumberOfValidRuns: 0x%1!x!, MaxRuns: 0x%2!x!, BytesReturned: 0x%3!I64x!

Fields #

NameDescription
A10_ExtentsDescriptor->NumberOfValidRuns HexInt32 → HexInt32
A11_MaxRuns HexInt32 → HexInt32
A12_*BytesReturned HexInt64 → HexInt64

Event ID 283 — Made an educated guess for remaining runs.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Made an educated guess for remaining runs. RemainingClusterCount: 0x%1!I64x!, NumberOfValidRuns: 0x%2!x!

Fields #

NameDescription
A10_RemainingClusterCount HexInt64 → HexInt64
A11_ExtentsDescriptor->NumberOfValidRuns HexInt32 → HexInt32

Event ID 284 — Made a wild guess for remaining runs.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Made a wild guess for remaining runs. RemainingClusterCount: 0x%1!I64x!, NumberOfValidRuns: 0x%2!x!

Fields #

NameDescription
A10_RemainingClusterCount HexInt64 → HexInt64
A11_ExtentsDescriptor->NumberOfValidRuns HexInt32 → HexInt32

Event ID 285 — NumberOfValidRuns: 0xA10_ExtentsDescriptor->NumberOfValidRuns!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NumberOfValidRuns: 0x%1!08x!, MaxRuns: 0x%2!08x!, Status: 0x%3!08x!, BytesReturned: 0x%4!I64x!

Fields #

NameDescription
A10_ExtentsDescriptor->NumberOfValidRuns HexInt32 → HexInt32
A11_MaxRuns HexInt32 → HexInt32
A12_Status HexInt32 → HexInt32
A13_*BytesReturned HexInt64 → HexInt64

Event ID 286 — BasePage: 0xA10_ExtentsDescriptor->Run[Index].BasePage!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

BasePage: 0x%1!-16I64x!, PageCount: 0x%2!-16I64x!

Fields #

NameDescription
A10_ExtentsDescriptor->Run[Index].BasePage HexInt64 → HexInt64
A11_ExtentsDescriptor->Run[Index].PageCount HexInt64 → HexInt64

Event ID 287 — About to zero range - ZeroStart: 0xA10_ZeroStart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

About to zero range - ZeroStart: 0x%1!016I64x!, ZeroEnd: 0x%2!016I64x!

Fields #

NameDescription
A10_ZeroStart HexInt64 → HexInt64
A11_ZeroEnd HexInt64 → HexInt64

Event ID 288 — Zeroed range - ZeroStart: 0xA10_ZeroStart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Zeroed range - ZeroStart: 0x%1!016I64x!, ZeroEnd: 0x%2!016I64x!

Fields #

NameDescription
A10_ZeroStart HexInt64 → HexInt64
A11_ZeroEnd HexInt64 → HexInt64

Event ID 289 — NtfsCommonQueryInformation: File information query not allowed as file was opened by ID without traversal privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonQueryInformation: File information query not allowed as file was opened by ID without traversal privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Ccb flags: 0x%10!08x!.

Event ID 290 — NtfsQueryCaseSensitiveInfo: Case sensitive info query not allowed without read attributes access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryCaseSensitiveInfo: Case sensitive info query not allowed without read attributes access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Ccb access flags: 0x%10!08x!, Granted access: 0x%11!08x!.

Event ID 291 — NtfsQueryNameInfo: Name info query not allowed as file was opened without traverse privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryNameInfo: Name info query not allowed as file was opened without traverse privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Ccb flags: 0x%10!08x!.

Event ID 292 — NtfsQueryLinksInfo: Link info query not allowed as file was opened without traverse privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryLinksInfo: Link info query not allowed as file was opened without traverse privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb flags: 0x%7!08x!.

Event ID 293 — NtfsSetCaseSensitiveInfo: Cannot mark root directory of a volume case-sensitive.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetCaseSensitiveInfo: Cannot mark root directory of a volume case-sensitive. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Device Object flags: 0x%10!08x!.

Event ID 294 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Fcb state: %7!x!.

Event ID 295 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, TxfNumWriters count: %7!d!.

Event ID 296 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Lcb: %7!p!, Link name: %8!S!, TxfNumWriters count: %9!d!.

Event ID 297 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened by ID.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened by ID. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Cleanup count: %7!d!.

Event ID 298 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles via either part of the long/short pair.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles via either part of the long/short pair. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Lcb: %7!p!, Link name: %8!S!, Link cleanup count: %9!d!, SplitPrimaryLcb: %10!p!, Split link name: %11!S!, Split link cleanup count: %12!d!.

Event ID 299 — NtfsSetRenameInfo: Can not rename a file marked for deletion.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetRenameInfo: Can not rename a file marked for deletion. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Fcb state: 0x%7!08x!, Lcb: %8!p!, link name: %9!S!, link name flag: 0x%10!08x!, link state: 0x%11!08x!.

Event ID 300 — NtfsSetRenameInfo: Can not rename a txf directory.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetRenameInfo: Can not rename a txf directory. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, File attributes: 0x%7!08x!.

Event ID 301 — NtfsSetRenameInfo: Can not rename into a system directory.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetRenameInfo: Can not rename into a system directory. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!.

Event ID 302 — NtfsSetRenameInfo: Can not rename a file that is part of a TxF transaction.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetRenameInfo: Can not rename a file that is part of a TxF transaction. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileAttributes: 0x%7!08x!, Rmstate: 0x%8!08x!.

Event ID 303 — NtfsSetRenameInfo: The file should not have in-memory directory descendents.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetRenameInfo: The file should not have in-memory directory descendents. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!.

Event ID 304 — NtfsSetRenameInfo: Child Scb mismatch.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetRenameInfo: Child Scb mismatch. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Potential child FileRef: %7!I64x!.

Event ID 305 — NtfsSetLinkInfo: Set link info is not allowed on txf directory.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetLinkInfo: Set link info is not allowed on txf directory. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileName: %7!S!.

Event ID 306 — NtfsSetLinkInfo: Set link info is not allowed on a file in a TxF transaction.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetLinkInfo: Set link info is not allowed on a file in a TxF transaction. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileName: %7!S!, TxfVisibleLinks: %8!d!.

Event ID 307 — NtfsSetLinkInfo: Set link info failed due to caller not having FILE_WRITE_ATTRIBUTES access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetLinkInfo: Set link info failed due to caller not having FILE_WRITE_ATTRIBUTES access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileName: %7!S!, SeAccessCheck status: %8!S!.

Event ID 308 — NtfsSetLinkInfo: Creating a link in system directory is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetLinkInfo: Creating a link in system directory is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, NewLinkName: %7!S!.

Event ID 309 — NtfsSetLinkInfo: Creating a link in $txf is not allowed if the RM is running.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetLinkInfo: Creating a link in $txf is not allowed if the RM is running. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, NewLinkName: %7!S!, Target RM state: %8!x!.

Event ID 310 — NtfsSetShortNameInfo: Can not set a short name on a deleted file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetShortNameInfo: Can not set a short name on a deleted file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Lcb: %7!p!, Link Name: %8!S!.

Event ID 311 — NtfsSetShortNameInfo: Can not set a short name on a file under the $TxF directory.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetShortNameInfo: Can not set a short name on a file under the $TxF directory. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Lcb: %7!p!, Link Name: %8!S!, Parent FileRef: %9!I64x!.

Event ID 312 — NtfsCheckScbForLinkRemoval: Existing handles are not allowed if Txf transaction is doing the rename.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckScbForLinkRemoval: Existing handles are not allowed if Txf transaction is doing the rename. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Stream cleanup count: %7!d!.

Event ID 313 — NtfsCheckScbForLinkRemoval: Not all open handles for the stream are by-id opens.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckScbForLinkRemoval: Not all open handles for the stream are by-id opens. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, ByID opens: %7!d!, Stream cleanup count: %8!d!.

Event ID 314 — NtfsStreamRename: Deny access due to encryption happening on source stream.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsStreamRename: Deny access due to encryption happening on source stream. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Scb state: 0x%10!08x! Scb HighWaterMark: %11!I64d!.

Event ID 315 — NtfsProcessTreeForRename: Deny access due to number of batch oplocks has grown.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsProcessTreeForRename: Deny access due to number of batch oplocks has grown. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Previous batch oplock count: %7!d!, current batch oplock count: %8!d!.

Event ID 316 — NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread(), Vcb: A11_Vcb, Fcb: A12_Fcb, LocalFlags: A13_LocalFlags->EntireFlags!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFlushVolumeFlushSingleFcb: Thread: %1!p!, Vcb: %2!p!, Fcb: %3!p!, LocalFlags: %4!#08x!

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_Fcb Pointer → HexInt64
A13_LocalFlags->EntireFlags HexInt32 → HexInt32

Event ID 317 — NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread(), Scb: A11_Scb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFlushVolumeFlushSingleFcb: Thread: %1!p!, Scb: %2!p!

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64
A11_Scb Pointer → HexInt64

Event ID 318 — NtfsFlushVolume: Thread: A10_PsGetCurrentThread(), Vcb: A11_Vcb, LocalFlags: A12_LocalFlags.EntireFlags!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFlushVolume: Thread: %1!p!, Vcb: %2!p!, LocalFlags: %3!#08x!

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12_LocalFlags.EntireFlags HexInt32 → HexInt32

Event ID 319 — NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on BitmapScb Scb: A10_Vcb->BitmapScb Vcb: A11_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on BitmapScb Scb: %1!p! Vcb: %2!p!

Fields #

NameDescription
A10_Vcb->BitmapScb Pointer → HexInt64
A11_Vcb Pointer → HexInt64

Event ID 320 — NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on MftScb Scb: A10_Vcb->MftScb Vcb: A11_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on MftScb Scb: %1!p! Vcb: %2!p!

Fields #

NameDescription
A10_Vcb->MftScb Pointer → HexInt64
A11_Vcb Pointer → HexInt64

Event ID 321 — NtfsFlushCompletionRoutine: Vcb A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb - Add context A11_Context into completion queue.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFlushCompletionRoutine: Vcb %1!p! - Add context %2!p! into completion queue

Fields #

NameDescription
A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb Pointer → HexInt64
A11_Context Pointer → HexInt64

Event ID 322 — NtfsFlushCompletionRoutine: Vcb A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb - Add context A11_Context into WorkQueue - Flink A12_NtfsData.DiskFlushContextCompletedWorkItem.List.Flink.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFlushCompletionRoutine: Vcb %1!p! - Add context %2!p! into WorkQueue - Flink %3!p!

Fields #

NameDescription
A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb Pointer → HexInt64
A11_Context Pointer → HexInt64

Event ID 323 — NtfsDiskFlushContextWorkItemProcessing: Process work item.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDiskFlushContextWorkItemProcessing: Process work item

Event ID 324 — NtfsDiskFlushContextWorkItemProcessing: Nothing to work on.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDiskFlushContextWorkItemProcessing: Nothing to work on

Event ID 325 — Irp: A10_Irp, IC: A11_IrpContext, Vcb: A12_IrpContext->Vcb, MinorCode: A13_IrpSp->MinorFunction!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Irp: %1!p!, IC: %2!p!, Vcb: %3!p!, MinorCode: %4!02x!, FsControlCode: 0x%5!08x!

Fields #

NameDescription
A10_Irp Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_IrpContext->Vcb Pointer → HexInt64
A13_IrpSp->MinorFunction HexInt32 → HexInt32
A14_FsControlCode HexInt32 → HexInt32

Event ID 326 — NtfsLockVolumeInternal: Cannot lock the volume.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLockVolumeInternal: Cannot lock the volume. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Vcb State: 0x%5!08x!, DisallowDismountCount: %6!d!, ExplicitLock: %7!d!, Volume CleanupCount: %8!d!, Handle count: %9!d!.

Event ID 327 — NtfsLockVolumeInternal: Volume is already locked.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLockVolumeInternal: Volume is already locked.Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Vcb State: 0x%5!08x!.

Event ID 328 — NtfsLockVolumeInternal: Failed to flush system files on the volume.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLockVolumeInternal: Failed to flush system files on the volume. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Flush Status: %5!S!.

Event ID 329 — NtfsLockVolumeInternal: Failed to flush system files on the volume.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLockVolumeInternal: Failed to flush system files on the volume.Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Flush Status: %5!S!.

Event ID 330 — NtfsLockVolumeInternal: Outstanding user files open after flush and retry.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLockVolumeInternal: Outstanding user files open after flush and retry. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Volume close count: %5!d!, System file close count: %6!d!, User handle count: %7!d!.

Event ID 331 — NtfsLockVolume: Cannot lock volume due to caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLockVolume: Cannot lock volume due to caller does not have manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 332 — NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Active RM count: %5!d!, Default RM Active: %6!d!.

Event ID 333 — A10___FUNCTION__: Setting RM at 0xA11_(PVOID)Vcb->TxfVcb.DefaultRm ({A12_(Vcb->TxfVcb.DefaultRm != NULL) ? _Vcb->TxfVcb.DefaultRm->RmId : ...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Setting RM at 0x%2!p! ({%3!S!}) up for auto-restart.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)Vcb->TxfVcb.DefaultRm Pointer → HexInt64
A12_(Vcb->TxfVcb.DefaultRm != NULL) ? _Vcb->TxfVcb.DefaultRm->RmId : NULL GUID → GUID

Event ID 334 — NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 335 — NtfsDismountVolume: IC: %1, Vcb: %2, Label: %3, DeviceName: %4.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDismountVolume: IC: %1!p!, Vcb: %2!p!, Label: %3!S!, DeviceName: %4!S!

Event ID 336 — NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 337 — NtfsDismountVolume: Cannot dismount volume due to volume being locked.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDismountVolume: Cannot dismount volume due to volume being locked. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, VcbState: 0x%5!08x!.

Event ID 338 — NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, VcbState: 0x%5!08x!, ReadOnlyCloseCount: %6!d!, CloseCount: %7!d!, SystemFileCloseCount: %8!d!.

Event ID 339 — NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 340 — NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 341 — NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 342 — NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 343 — NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 344 — NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege or this is not a volume open.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege or this is not a volume open. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!, TypeOfOpen: %6!d!.

Event ID 345 — NtfsCreateUsnJournal: Cannot create Usn journal due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCreateUsnJournal: Cannot create Usn journal due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!, Irp Request Mode: %6!d!.

Event ID 346 — NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 347 — NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 348 — NtfsFindFilesOwnedBySid: Caller not having manage volume privilege, backup access or can bypass traverse checks.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFindFilesOwnedBySid: Caller not having manage volume privilege, backup access or can bypass traverse checks. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!, Ccb flags: 0x%6!08x!.

Event ID 349 — NtfsFindFilesOwnedBySid: Caller not having manage volume privilege or backup access and is not admin.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFindFilesOwnedBySid: Caller not having manage volume privilege or backup access and is not admin. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!, Ccb flags: 0x%6!08x!, CallerId: %7!d!, Context owner ID: %8!d!.

Event ID 350 — NtfsSetSparse: Caller does not have appropriate write access to the stream.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetSparse: Caller does not have appropriate write access to the stream. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FullFileName: %7!S!, Ccb access flags: 0x%8!08x!, FileObject write access: %9!d!.

Event ID 351 — NtfsSetSparse: Cannot desparse encrypted file without write data access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetSparse: Cannot desparse encrypted file without write data access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FullFileName: %7!S!, Ccb access flags: 0x%8!08x!, Scb attributes: 0x%9!08x!.

Event ID 352 — NtfsZeroRange: User mode caller not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsZeroRange: User mode caller not allowed. Thread: %1!p!, Zero flags: 0x%2!08x!, Irp Requestor Mode: %3!d!.

Fields #

NameDescription
A10_PsGetCurrentThread() Pointer → HexInt64
A11_ZeroFlags HexInt32 → HexInt32
A12_Irp->RequestorMode Int32 → int

Event ID 353 — IC: A10_IrpContext, Scb: A11_Scb, FileObject: A12_IrpSp->FileObject.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

IC: %1!p!, Scb: %2!p!, FileObject: %3!p!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Scb Pointer → HexInt64
A12_IrpSp->FileObject Pointer → HexInt64

Event ID 354 — IC: A10_IrpContext, EncryptionOperation: 0xA11_EncryptionOperation!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

IC: %1!p!, EncryptionOperation: 0x%2!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_EncryptionOperation HexInt32 → HexInt32

Event ID 355 — NtfsReadRawEncrypted: Caller does not have backup access or read data access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsReadRawEncrypted: Caller does not have backup access or read data access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 356 — NtfsWriteRawEncrypted: Caller does not have write data access or restore access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWriteRawEncrypted: Caller does not have write data access or restore access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 357 — NtfsWriteRawEncrypted: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsWriteRawEncrypted: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 358 — NtfsLookupStreamFromCluster: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsLookupStreamFromCluster: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 359 — NtfsChangeVolumeSize: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsChangeVolumeSize: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 360 — NtfsChangeVolumeSize (A10_Vcb): Calling NtfsFreeRecentlyDeallocated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsChangeVolumeSize (%1!p!): Calling NtfsFreeRecentlyDeallocated

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 361 — NtfsChangeVolumeSize (A10_Vcb): Done calling NtfsFreeRecentlyDeallocated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsChangeVolumeSize (%1!p!): Done calling NtfsFreeRecentlyDeallocated

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 362 — NtfsMarkHandle: Caller does not have a valid volume handle or manage volume access or is not kernel model caller.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: Caller does not have a valid volume handle or manage volume access or is not kernel model caller. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FullFileName: %7!S!, Ccb access flags: 0x%8!08x!, HandleInfo flags: 0x%9!08x!, Irp Requestor Mode: %10!d!.

Event ID 363 — NtfsMarkHandle: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 364 — NtfsMarkHandle: Cannot deny defrag.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: Cannot deny defrag. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Persist flags: 0x%10!08x!, HandleInfo flags: 0x%11!08x!.

Event ID 365 — NtfsMarkHandle: Cannot deny Frs consolidation.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: Cannot deny Frs consolidation. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState2: 0x%7!08x!, Scb: %8!p!, Scb Type Code: 0x%9!x!, Scb Name: %10!S!, Persist flags: 0x%11!08x!, HandleInfo flags: 0x%12!08x!.

Event ID 366 — NtfsMarkHandle: Cannot filter metadata.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: Cannot filter metadata. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, Scb: %8!p!, Scb Type Code: 0x%9!x!, Scb Name: %10!S!, Persist flags: 0x%11!08x!, HandleInfo flags: 0x%12!08x!, Irp RequestorMode: %13!d!.

Event ID 367 — NtfsMarkHandle: Mark handle is not allowed on system files.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: Mark handle is not allowed on system files. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FcbState: 0x%7!08x!, HandleInfo flags: %8!x!.

Event ID 368 — NtfsMarkHandle: File already has user writable references.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: File already has user writable references. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, HandleInfo: 0x%10!08x!.

Event ID 369 — NtfsMarkHandle: File was granted write access previously but no oplocks were broken.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMarkHandle: File was granted write access previously but no oplocks were broken. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Writers: %10!d!.

Event ID 370 — NtfsPrefetchFile: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPrefetchFile: Caller not having manage volume privilege. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 371 — NtfsSetZeroOnDeallocate: Only allowed on regular user files opened for write.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetZeroOnDeallocate: Only allowed on regular user files opened for write. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, TypeOfOpen: %5!d!, WriteAccess: %6!d!, Fcb: %7!p!, FileRef: 0x%8!I64x!, FcbState: %9!x!, Scb AttributeTypeCode: 0x%10!x!, Ccb FullFileName: %11!S!.

Event ID 372 — NtfsSetShortNameBehavior: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetShortNameBehavior: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 373 — Setting VCB_EXT_CHAR_STATE_ALLOW_EXT_CHAR for volume 0xA10_(PVOID)Vcb to A11_InputParameter.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Setting VCB_EXT_CHAR_STATE_ALLOW_EXT_CHAR for volume 0x%1!p! to %2!u!.

Fields #

NameDescription
A10_(PVOID)Vcb Pointer → HexInt64
A11_InputParameter UInt32 → unsignedInt

Event ID 374 — NtfsQueryPagefileEncryption: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryPagefileEncryption: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 375 — NtfsQueryPagefileEncryption: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryPagefileEncryption: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 376 — NtfsResetVolsnapBehaviorForVolume: Volsnap hints are disabled by registry.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsResetVolsnapBehaviorForVolume: Volsnap hints are disabled by registry. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, NtfsData Flags: %5!x!.

Event ID 377 — NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 378 — Resetting Volsnap behavior for VCB = 0xA10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Resetting Volsnap behavior for VCB = 0x%1!p!.  New state is 0x%2!x!.

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->VcbState HexInt32 → HexInt32

Event ID 379 — NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 380 — NtfsCorruptionHandling: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCorruptionHandling: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Ccb access flags: 0x%5!08x!.

Event ID 381 — NtfsGlobalCorruptionHandling: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGlobalCorruptionHandling: Caller does not have manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!.

Event ID 382 — Scrub resume from SystemScbIndex: A10_ScrubResumeContext.SystemScbIndex Vcn: A11_ScrubResumeContext.ResumeVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scrub resume from SystemScbIndex: %1!u! Vcn: %2!#I64x! + %3!#x!

Fields #

NameDescription
A10_ScrubResumeContext.SystemScbIndex UInt32 → unsignedInt
A11_ScrubResumeContext.ResumeVcn HexInt64 → HexInt64
A12_ScrubResumeContext.ResumeVcnOffset HexInt32 → HexInt32

Event ID 383 — Scb:A10_Scb Scrub resume from Vcn: A11_ScrubResumeContext.ResumeVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Scrub resume from Vcn: %2!#I64x! + %3!#x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_ScrubResumeContext.ResumeVcn HexInt64 → HexInt64
A12_ScrubResumeContext.ResumeVcnOffset HexInt32 → HexInt32

Event ID 384 — Scrub SystemScbIndex: A10_ScrubResumeContext.SystemScbIndex.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scrub SystemScbIndex: %1!u!

Fields #

NameDescription
A10_ScrubResumeContext.SystemScbIndex UInt32 → unsignedInt

Event ID 385 — NtfsScrubData: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsScrubData: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, TypeOfOpen: %5!d!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 386 — Scrub not supported for Txf file, Scb: A10_Scb, TxfScb: A11_Scb->TxfScb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scrub not supported for Txf file, Scb: %1!p!, TxfScb: %2!p!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Scb->TxfScb Pointer → HexInt64

Event ID 387 — Scrub SCRUB_DATA_INPUT_FLAG_SKIP_NON_INTEGRITY_DATA is request.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scrub SCRUB_DATA_INPUT_FLAG_SKIP_NON_INTEGRITY_DATA is request. noop

Event ID 388 — Scb:A10_Scb ScrubInternal OperationStatus: A11_ScrubContext.OperationStatus Repaired: A12_ScrubContext.NumberOfBytesRepaired!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! ScrubInternal OperationStatus: %2!S! Repaired: %3!#I64x! Failed: %4!#I64x! FileOffset: %5!#I64x! Length: %6!#I64x! ParityExtentCount: %7!u!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_ScrubContext.OperationStatus HexInt32 → NTStatus
A12_ScrubContext.NumberOfBytesRepaired HexInt64 → HexInt64
A13_ScrubContext.NumberOfBytesFailed HexInt64 → HexInt64
A14_ScrubContext.ErrorFileOffset HexInt64 → HexInt64
A15_ScrubContext.ErrorLength HexInt64 → HexInt64
A16_ScrubContext.ParityExtentData->NumberOfParityExtents UInt32 → unsignedInt

Event ID 389 — Scb:A10_Scb ScrubInternal Status: A11_Status Repaired: A12_ScrubContext.NumberOfBytesRepaired!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! ScrubInternal Status: %2!S! Repaired: %3!#I64x! Failed: %4!#I64x! ParityExtentCount: %5!u!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Status HexInt32 → NTStatus
A12_ScrubContext.NumberOfBytesRepaired HexInt64 → HexInt64
A13_ScrubContext.NumberOfBytesFailed HexInt64 → HexInt64
A14_ScrubContext.ParityExtentData->NumberOfParityExtents UInt32 → unsignedInt

Event ID 390 — InternalFileReference: A10_InternalFileReference.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

InternalFileReference: %1!u!

Fields #

NameDescription
A10_InternalFileReference UInt32 → unsignedInt

Event ID 391 — InternalFileReference:A10_InternalFileReference.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

InternalFileReference:%1!u!

Fields #

NameDescription
A10_InternalFileReference UInt32 → unsignedInt

Event ID 392 — Scb:A10_Scb Incomplete IoCount:A11_ScrubIoCount Cancel:A12_Irp->Cancel ParityExtentCount:A13_ScrubContext.ParityExtentData->NumberOfParityExtents.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Incomplete IoCount:%2!u! Cancel:%3!u! ParityExtentCount:%4!u!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_ScrubIoCount UInt32 → unsignedInt
A12_Irp->Cancel UInt32 → unsignedInt
A13_ScrubContext.ParityExtentData->NumberOfParityExtents UInt32 → unsignedInt

Event ID 393 — Scb:%1 Scrub skipping resident attribute (d) (%2).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Scrub skipping resident attribute (d) (%2!S!)

Event ID 394 — Scb:%1 Scrub skipping resident attribute (%2).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Scrub skipping resident attribute (%2!S!)

Event ID 395 — Scb:A10_Scb Scrub StartingVcn.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Scrub StartingVcn(%2!#I64d!) is negative

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn Int64 → long

Event ID 396 — Scb:A10_Scb Scrub starting vcn is beyond VDL.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Scrub starting vcn is beyond VDL (FileOffset: %2!#I64x!, SectorAlignedVdl: %3!#I64x!)

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_FileScrubOffset HexInt64 → HexInt64
A12_SectorAlignedVdl HexInt64 → HexInt64

Event ID 397 — Scb:A10_Scb Scrub no more Mcb entries from StartingVcn:A11_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Scrub no more Mcb entries from StartingVcn:%2!#I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn HexInt64 → HexInt64

Event ID 398 — Scb:A10_Scb Scrub skipping UNUSED_LCN Vcn: A11_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! Scrub skipping UNUSED_LCN Vcn: %2!#I64x!, ClusterCount: %3!#I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn HexInt64 → HexInt64
A12_ClusterCount HexInt64 → HexInt64

Event ID 399 — Scb:A10_Scb StartingVcn:A11_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! StartingVcn:%2!#I64x! is beyond Vdl

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn HexInt64 → HexInt64

Event ID 400 — Scb:A10_Scb ScrubDsmRange [A11_DsmRange.StartingOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! ScrubDsmRange [%2!#I64x!,%3!#I64x!) Length:%4!#I64x! (Bytes) StartingVcn:%5!#I64x! + %6!#x! SectorAlignedVdl:%7!#I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_DsmRange.StartingOffset HexInt64 → HexInt64
A12_DsmRange.StartingOffset + DsmRange.LengthInBytes HexInt64 → HexInt64
A13_DsmRange.LengthInBytes HexInt64 → HexInt64
A14_StartingVcn HexInt64 → HexInt64
A15_StartingVcnOffset HexInt32 → HexInt32
A16_SectorAlignedVdl HexInt64 → HexInt64

Event ID 401 — Scrub found problems Scb: A10_Scb Vcn A11_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scrub found problems Scb: %1!p! Vcn %2!#I64x! FileOffset: %3!#I64x! Length: %4!#I64x! Status: %5!S! BytesFailed: %6!#I64x! BytesRepaired: %7!#I64x! NewParityExtents: %8!u!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn HexInt64 → HexInt64
A12_ScrubContext->ErrorFileOffset HexInt64 → HexInt64
A13_ScrubbedLength HexInt64 → HexInt64
A14_ScrubContext->OperationStatus HexInt32 → NTStatus
A15_ScrubContext->NumberOfBytesFailed HexInt64 → HexInt64
A16_ScrubContext->NumberOfBytesRepaired HexInt64 → HexInt64
A17_NewParityExtentCount UInt32 → unsignedInt

Event ID 402 — Scb:A10_Scb DsmAction_Scrub call failed, Status: A11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! DsmAction_Scrub call failed, Status: %2!S!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Status HexInt32 → NTStatus

Event ID 403 — Scb:A10_Scb DsmAction_Scrub operation failed, Status: A11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! DsmAction_Scrub operation failed, Status: %2!S!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Status HexInt32 → NTStatus

Event ID 404 — FSCTL_REPAIR_COPIES not supported for Txf file, Scb: A10_Scb, TxfScb: A11_Scb->TxfScb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FSCTL_REPAIR_COPIES not supported for Txf file, Scb: %1!p!, TxfScb: %2!p!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Scb->TxfScb Pointer → HexInt64

Event ID 405 — Scb:%1 FSCTL_REPAIR_COPIES skipping resident attribute (d) (%2).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! FSCTL_REPAIR_COPIES skipping resident attribute (d) (%2!S!)

Event ID 406 — Scb:%1 FSCTL_REPAIR_COPIES skipping resident attribute (%2).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! FSCTL_REPAIR_COPIES skipping resident attribute (%2!S!)

Event ID 407 — FSCTL_REPAIR_COPIES interrupted by thread termination.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FSCTL_REPAIR_COPIES interrupted by thread termination.

Event ID 408 — FSCTL_REPAIR_COPIES canceled.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FSCTL_REPAIR_COPIES canceled

Event ID 409 — Scb:A10_Scb FSCTL_REPAIR_COPIES no more Mcb entries from StartingVcn:A11_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! FSCTL_REPAIR_COPIES no more Mcb entries from StartingVcn:%2!#I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn HexInt64 → HexInt64

Event ID 410 — Scb:A10_Scb FSCTL_REPAIR_COPIES No more Mcb entries (unallocated) from StartingVcn:A11_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! FSCTL_REPAIR_COPIES No more Mcb entries (unallocated) from StartingVcn:%2!#I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn HexInt64 → HexInt64

Event ID 411 — Scb:A10_Scb FSCTL_REPAIR_COPIES skipping UNUSED_LCN Vcn: A11_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! FSCTL_REPAIR_COPIES skipping UNUSED_LCN Vcn: %2!#I64x!, ClusterCount: %3!#I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartingVcn HexInt64 → HexInt64
A12_ClusterCount HexInt64 → HexInt64

Event ID 412 — Scb:A10_Scb RepairDsmRange [A11_RepairDataSetRange->StartingOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! RepairDsmRange [%2!#I64x!,%3!#I64x!) Length:%4!#I64x! (Bytes) FileOffset: %5!#I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_RepairDataSetRange->StartingOffset HexInt64 → HexInt64
A12_RepairDataSetRange->StartingOffset + RepairDataSetRange->LengthInBytes HexInt64 → HexInt64
A13_RepairDataSetRange->LengthInBytes HexInt64 → HexInt64
A14_RepairFileOffset HexInt64 → HexInt64

Event ID 413 — Scb:A10_Scb DsmAction_Repair call failed, Status: A11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! DsmAction_Repair call failed, Status: %2!S!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Status HexInt32 → NTStatus

Event ID 414 — Scb:A10_Scb DsmAction_Repair operation failed, Status: A11_IrpStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! DsmAction_Repair operation failed, Status: %2!S!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_IrpStatus HexInt32 → NTStatus

Event ID 415 — Scb:A10_Scb DsmAction_Repair completed, IrpStatus: A11_RepairCopiesOutput->Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb:%1!p! DsmAction_Repair completed, IrpStatus: %2!S!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_RepairCopiesOutput->Status HexInt32 → NTStatus

Event ID 416 — NtfsQueryCachedRuns: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryCachedRuns: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, TypeOfOpen: %5!d!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 417 — NtfsQueryStorageClasses: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryStorageClasses: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, TypeOfOpen: %5!d!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 418 — NtfsQueryRegionInfo: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryRegionInfo: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, TypeOfOpen: %5!d!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 419 — NtfsUnloadFile: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUnloadFile: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, TypeOfOpen: %5!d!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 420 — NtfsCheckForSection: File already has image section.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckForSection: File already has image section. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!.

Event ID 421 — NtfsShuffleFile: User mode caller is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsShuffleFile: User mode caller is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, TypeOfOpen: %5!d!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Irp RequestorMode: %9!d!.

Event ID 422 — NtfsShuffleFile: Denying access due to volume is locked.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsShuffleFile: Denying access due to volume is locked. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, Ccb FullFileName: %8!S!, VcbState: 0x%9!08x!.

Event ID 423 — NtfsShuffleFile: Defrag is denied.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsShuffleFile: Defrag is denied. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Persist flags: 0x%10!08x!, Ccb flags: 0x%11!08x!.

Event ID 424 — NtfsShuffleFile: Denying access due to conflicting with read-only state.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsShuffleFile: Denying access due to conflicting with read-only state. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileAttributes: 0x%7!08x!, SL control flags: 0x%8!08x!.

Event ID 425 — NtfsRearrangeFile: User mode caller is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRearrangeFile: User mode caller is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb FullFileName: %7!S!, Irp RequestorMode: %8!d!.

Event ID 426 — NtfsRearrangeFile: Denying access due to volume is locked.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRearrangeFile: Denying access due to volume is locked. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb FullFileName: %7!S!, VcbState: 0x%8!08x!.

Event ID 427 — NtfsRearrangeFile: Defrag is denied.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRearrangeFile: Defrag is denied. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Persist flags: 0x%10!08x!, Ccb flags: 0x%11!08x!.

Event ID 428 — NtfsShuffleFile: Denying access due to conflicting with read-only state.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsShuffleFile: Denying access due to conflicting with read-only state. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, FileAttributes: 0x%7!08x!, SL control flags: 0x%8!08x!.

Event ID 429 — NtfsSparseOverAllocate: Caller does not have appropriate write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSparseOverAllocate: Caller does not have appropriate write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, FileRef: %5!I64x!, FullFileName: %6!S!, Ccb access flags: %7!x!.

Event ID 430 — NtfsInitiateFileMetadataOptimization: Only allowed on regular user files/directories opened for write.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsInitiateFileMetadataOptimization: Only allowed on regular user files/directories opened for write. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, Scb AttributeTypeCode: %8!x!, FcbState2: %9!x!, Ccb FullFileName: %10!S!, Ccb Access flags: %11!x!, Ccb Flags2: %12!x!.

Event ID 431 — NtfsQueryFileMetadataOptimization: Only allowed on regular user files/directories opened for read.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryFileMetadataOptimization: Only allowed on regular user files/directories opened for read. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Scb AttributeTypeCode: 0x%8!x!, Ccb FullFileName: %9!S!, Ccb Access flags: 0x%10!08x!.

Event ID 432 — NtfsCleanVolumeMetadata: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCleanVolumeMetadata: Caller not having manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 433 — NtfsEnumOnMountToDeleteWorker(%1,%2): Open status=0x%3, path="%4".

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEnumOnMountToDeleteWorker(%1!p!,%2!p!): Open status=0x%3!x!, path="%4!S!"

Event ID 434 — NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread()): Enumerate status=0xA12_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEnumOnMountToDeleteWorker(%1!p!,%2!p!): Enumerate status=0x%3!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_PsGetCurrentThread() Pointer → HexInt64
A12_Status HexInt32 → HexInt32

Event ID 435 — NtfsEnumMountWorker(%1,%2): Open status=0x%3, file="%4".

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEnumMountWorker(%1!p!,%2!p!): Open status=0x%3!x!, file="%4!S!"

Event ID 436 — NtfsEnumMountWorker(A10_Vcb,A11_PsGetCurrentThread()): Close status=0xA12_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEnumMountWorker(%1!p!,%2!p!): Close status=0x%3!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_PsGetCurrentThread() Pointer → HexInt64
A12_Status HexInt32 → HexInt32

Event ID 437 — NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread()): Close dir status=0xA12_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEnumOnMountToDeleteWorker(%1!p!,%2!p!): Close dir status=0x%3!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_PsGetCurrentThread() Pointer → HexInt64
A12_Status HexInt32 → HexInt32

Event ID 438 — NtfsCleanVolumeMetadata: Caller not having manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCleanVolumeMetadata: Caller not having manage volume privilege. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!, EffectiveMode: %10!d!.

Event ID 439 — SCB: A10_Scb, StartOffset: 0xA11_StartOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

SCB: %1!p!, StartOffset: 0x%2!I64x!, Length: 0x%3!I64x!, StartVcn=0x%4!I64x!, BeyondEndVcn=0x%5!I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_StartOffset HexInt64 → HexInt64
A12_Length HexInt64 → HexInt64
A13_StartVcn HexInt64 → HexInt64
A14_BeyondEndVcn HexInt64 → HexInt64

Event ID 440 — FsLibGetBadAddressRanges returned Status: A10_Status, NumBadRanges: 0xA11_Output->NumBadRanges.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FsLibGetBadAddressRanges returned Status: %1, NumBadRanges: 0x%2!x!

Fields #

NameDescription
A10_Status HexInt32 → NTStatus
A11_Output->NumBadRanges HexInt32 → HexInt32

Event ID 441 — FsInputRangeIndex: A10_FsInputRangeIndex, FileOffset: 0xA11_FsInputRanges[FsInputRangeIndex].FileOffset!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FsInputRangeIndex: %1!u!, FileOffset: 0x%2!I64x!, VolumeOffset: 0x%3!I64x!, LengthInBytes: 0x%4!I64x!

Fields #

NameDescription
A10_FsInputRangeIndex UInt32 → unsignedInt
A11_FsInputRanges[FsInputRangeIndex].FileOffset HexInt64 → HexInt64
A12_FsInputRanges[FsInputRangeIndex].VolumeOffset HexInt64 → HexInt64
A13_FsInputRanges[FsInputRangeIndex].LengthInBytes HexInt64 → HexInt64

Event ID 442 — Scb: A10_Scb, Status: A11_Status, AbnormalTermination: A12_(BOOLEAN)AbnormalTermination().

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb: %1!p!, Status: %2!S!, AbnormalTermination: %3!S!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Status HexInt32 → NTStatus
A12_(BOOLEAN)AbnormalTermination() UInt8 → unsignedByte

Event ID 443 — Scb: A10_Scb, Status: A11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Scb: %1!p!, Status: %2!S!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Status HexInt32 → NTStatus

Event ID 444 — NtfsEncryptionKeyCtl: Caller does not have SE_TCB_PRIVILEGE.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsEncryptionKeyCtl: Caller does not have SE_TCB_PRIVILEGE. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!.

Event ID 445 — Logic error of posting close to work queue.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Logic error of posting close to work queue.

Event ID 446 — NtfsFindPrefixHashEntry: {Hash table: %1} {ParentScb: %2, '%3'} {RemainingName: '%4'}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFindPrefixHashEntry: {Hash table: %1!p!} {ParentScb: %2!p!, '%3!S!'} {RemainingName: '%4!S!'}

Event ID 447 — NtfsFindPrefixHashEntry: {Lcb: NULL}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFindPrefixHashEntry: {Lcb: NULL}

Event ID 448 — NtfsFindPrefixHashEntry: {Lcb: %1, '%2'}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFindPrefixHashEntry: {Lcb: %1!p!, '%2!S!'}

Event ID 449 — NtfsFindPrefixHashEntry: {Lcb not found}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFindPrefixHashEntry: {Lcb not found}

Event ID 450 — NtfsInsertHashEntry: {Hash table: %1} {HashValue: %2!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsInsertHashEntry: {Hash table: %1!p!} {HashValue: %2!08x!} {FullNameLength: %3!d!} {Lcb: %4!p!, '%5!S!'}

Event ID 451 — NtfsRemoveHashEntry: {Hash table: %1} {HashValue: %2!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveHashEntry: {Hash table: %1!p!} {HashValue: %2!08x!} {HashLcb: %3!p!, '%4!S!'}

Event ID 452 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Checkpoint injection.  Count %2!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->CheckpointInjectionCount Int32 → int

Event ID 453 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Log %2!d!%!PCT! full.  Wait for CC to flush metadata first. Count %3!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_PercentFull Int32 → int
A12_Vcb->WaitForCcLoggedDataActivityCount Int32 → int

Event ID 454 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Done waiting for CC to flush metadata

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 455 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Injected checkpoint.

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 456 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Start of checkpoint

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 457 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Clean checkpoint. Count %2!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->CleanCheckpointCount Int32 → int

Event ID 458 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Overflowed DPT. Count %2!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->OverflowedDPTCount Int32 → int

Event ID 459 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Fuzzy checkpoint. Count %2!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->FuzzyCheckpointCount Int32 → int

Event ID 460 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Flush oldest FO.  Count %2!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Vcb->FlushOldestFOCount Int32 → int

Event ID 461 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Flush starts with FRef %2!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_NtfsFullSegmentNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64

Event ID 462 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Flush ends.  FO %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_DirtyPageContext.OldestFileObject Pointer → HexInt64

Event ID 463 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Checkpoint completed.

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 464 — Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p!.  Leaving NtfsCheckpointVolume.

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 465 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction IC: %1!p!, TransactionId: 0x%2!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->TransactionId HexInt32 → HexInt32

Event ID 466 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction IC: %1!p!, TransactionId: 0x%2!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->TransactionId HexInt32 → HexInt32

Event ID 467 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Pre NtfsWriteLog failure A13_IrpContext->ExceptionStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction (%1!p!,%2!p!,%3!p!): Pre NtfsWriteLog failure %4!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->OriginatingIrp Pointer → HexInt64
A12_PsGetCurrentThread() Pointer → HexInt64
A13_IrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 468 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Post NtfsWriteLog failure A13_IrpContext->ExceptionStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction (%1!p!,%2!p!,%3!p!): Post NtfsWriteLog failure %4!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->OriginatingIrp Pointer → HexInt64
A12_PsGetCurrentThread() Pointer → HexInt64
A13_IrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 469 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): LfsFlushToLsn failure A13_IrpContext->ExceptionStatus Count A14_FailedFlushCount.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction (%1!p!,%2!p!,%3!p!): LfsFlushToLsn failure %4!x! Count %5!d!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->OriginatingIrp Pointer → HexInt64
A12_PsGetCurrentThread() Pointer → HexInt64
A13_IrpContext->ExceptionStatus HexInt32 → HexInt32
A14_FailedFlushCount Int32 → int

Event ID 470 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Pre NtfsProcessNewLengthQueue failure A13_IrpContext->ExceptionStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction (%1!p!,%2!p!,%3!p!): Pre NtfsProcessNewLengthQueue failure %4!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->OriginatingIrp Pointer → HexInt64
A12_PsGetCurrentThread() Pointer → HexInt64
A13_IrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 471 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Post NtfsProcessNewLengthQueue failure A13_IrpContext->ExceptionStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction (%1!p!,%2!p!,%3!p!): Post NtfsProcessNewLengthQueue failure %4!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->OriginatingIrp Pointer → HexInt64
A12_PsGetCurrentThread() Pointer → HexInt64
A13_IrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 472 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction IC: %1!p!, TransactionId: 0x%2!08x! Completed

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->TransactionId HexInt32 → HexInt32

Event ID 473 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommitCurrentTransaction IC: %1!p!, TransactionId: 0x%2!08x! Completed

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->TransactionId HexInt32 → HexInt32

Event ID 474 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Entering - ActiveLsn: A11_ActiveLsn->QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Entering - ActiveLsn: %2!I64x!, ClearAll: %3!S!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_ActiveLsn->QuadPart HexInt64 → HexInt64
A12_ClearAll UInt32 → unsignedInt

Event ID 475 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! empty list - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 476 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! empty list  - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 477 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found frozen deallocated clusters with A11_Clusters->ClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Found frozen deallocated clusters with %2!I64x! clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Clusters->ClusterCount HexInt64 → HexInt64

Event ID 478 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - No actionable deallocated clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 479 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - No actionable deallocated clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 480 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found a deallocated clusters A11_Clusters with A12_Clusters->ClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Found a deallocated clusters %2!p! with %3!I64x! clusters, Lsn: %4!I64x!, Flags: %5!08x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Clusters Pointer → HexInt64
A12_Clusters->ClusterCount HexInt64 → HexInt64
A13_Clusters->Lsn.QuadPart HexInt64 → HexInt64
A14_Clusters->Flags HexInt32 → HexInt32

Event ID 481 — Vcb: A10_Vcb, Processing range.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb: %1!p!, Processing range. DeallocatedClusters: %2!p!, RunIndex: %3!d!, StartingLcn: %4!I64x!, ClusterCount: %5!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Clusters Pointer → HexInt64
A12_i Int32 → int
A13_StartingLcn HexInt64 → HexInt64
A14_ClusterCount HexInt64 → HexInt64

Event ID 482 — Looking for dangling MDLs.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Looking for dangling MDLs

Event ID 483 — FsLibGroupSubExtentsByDanglingMdl failed: A10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FsLibGroupSubExtentsByDanglingMdl failed: %1

Fields #

NameDescription
A10_Status HexInt32 → NTStatus

Event ID 484 — FsLibAddBaseMcbEntryEx failed: A10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

FsLibAddBaseMcbEntryEx failed: %1

Fields #

NameDescription
A10_Status HexInt32 → NTStatus

Event ID 485 — NtfsAddToMatchingDeallocatedClusters( ExtentsWithoutDanglingMdl ) failed: A10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddToMatchingDeallocatedClusters( ExtentsWithoutDanglingMdl ) failed: %1

Fields #

NameDescription
A10_Status HexInt32 → NTStatus

Event ID 486 — NtfsAddToMatchingDeallocatedClusters( ExtentsWithDanglingMdl ) failed: A10_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddToMatchingDeallocatedClusters( ExtentsWithDanglingMdl ) failed: %1

Fields #

NameDescription
A10_Status HexInt32 → NTStatus

Event ID 487 — No sub extents has dangling MDL.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

No sub extents has dangling MDL

Event ID 488 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Telling volsnap freeing at A11_StartingLcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Telling volsnap freeing at %2!I64x! for %3!x! clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_StartingLcn HexInt64 → HexInt64
A12_(ULONG)ClusterCount HexInt32 → HexInt32

Event ID 489 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Volsnap responsed with freeing at A11_StartingLcn + StartingIndex!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Volsnap responsed with freeing at %2!I64x! for %3!x! clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_StartingLcn + StartingIndex HexInt64 → HexInt64
A12_runLength HexInt32 → HexInt32

Event ID 490 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Got error 0xA11_Status from below.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Got error 0x%2!x! from below

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Status HexInt32 → HexInt32

Event ID 491 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Deleting MarkUnusedContext A11_MarkUnusedContext.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Deleting MarkUnusedContext %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_MarkUnusedContext Pointer → HexInt64

Event ID 492 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Leaving.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFreeRecentlyDeallocated: Vcb %1!p! - Leaving

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 493 — NtfsRemoveNtfsMcbEntry Scb: A10_Mcb->Scb, Mcb: A11_Mcb, Vcn: 0xA12_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveNtfsMcbEntry Scb: %1!p!, Mcb: %2!p!, Vcn: 0x%3!I64x!, Length: 0x%4!I64x!

Fields #

NameDescription
A10_Mcb->Scb Pointer → HexInt64
A11_Mcb Pointer → HexInt64
A12_StartingVcn HexInt64 → HexInt64
A13_Count HexInt64 → HexInt64

Event ID 494 — NtfsRemoveNtfsMcbEntry Mcb: A10_Mcb Completed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRemoveNtfsMcbEntry Mcb: %1!p! Completed.

Fields #

NameDescription
A10_Mcb Pointer → HexInt64

Event ID 495 — NtfsAddNtfsMcbEntry Scb: A10_Mcb->Scb, Mcb: A11_Mcb, Vcn: 0xA12_Vcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddNtfsMcbEntry Scb: %1!p!, Mcb: %2!p!, Vcn: 0x%3!I64x!, Lcn: 0x%4!I64x!, Length: 0x%5!I64x!

Fields #

NameDescription
A10_Mcb->Scb Pointer → HexInt64
A11_Mcb Pointer → HexInt64
A12_Vcn HexInt64 → HexInt64
A13_Lcn HexInt64 → HexInt64
A14_RunCount HexInt64 → HexInt64

Event ID 496 — NtfsAddNtfsMcbEntry Mcb: A10_Mcb, Result: A11_Result.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAddNtfsMcbEntry Mcb: %1!p!, Result: %2!S!

Fields #

NameDescription
A10_Mcb Pointer → HexInt64
A11_Result UInt32 → unsignedInt

Event ID 497 — NtfsUnloadNtfsMcbRange Scb: A10_Mcb->Scb, Mcb: A11_Mcb, StartVcn: 0xA12_StartingVcn!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUnloadNtfsMcbRange Scb: %1!p!, Mcb: %2!p!, StartVcn: 0x%3!I64x!, EndVcn: 0x%4!I64x!, TruncateOnly: %5!S!

Fields #

NameDescription
A10_Mcb->Scb Pointer → HexInt64
A11_Mcb Pointer → HexInt64
A12_StartingVcn HexInt64 → HexInt64
A13_EndingVcn HexInt64 → HexInt64
A14_TruncateOnly UInt32 → unsignedInt

Event ID 498 — NtfsUnloadNtfsMcbRange Mcb: A10_Mcb Completed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUnloadNtfsMcbRange Mcb: %1!p! Completed.

Fields #

NameDescription
A10_Mcb Pointer → HexInt64

Event ID 499 — Valid NTFS boot sector.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Valid NTFS boot sector. Vcb: %1!p!; BootSector: %2!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_BootSector Pointer → HexInt64

Event ID 500 — Not an NTFS boot sector.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Not an NTFS boot sector. Vcb: %1!p!; BootSector: %2!p!; CheckNumber: %3!d!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_BootSector Pointer → HexInt64
A12_CheckNumber Int32 → int

Event ID 501 — NtfsMountVolume: Vcb:A10_Vcb, IC:A11_IrpContext, Growing allocation for Mft's Attribute List failed with exception:0xA12_IrpContext->ExceptionStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMountVolume: Vcb:%1!p!, IC:%2!p!, Growing allocation for Mft's Attribute List failed with exception:0x%3!x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_IrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 502 — NtfsMountVolume: IC: %1, Vcb: %2, Label: %3, DeviceName: %4.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsMountVolume: IC: %1!p!, Vcb: %2!p!, Label: %3!S!, DeviceName: %4!S!

Event ID 503 — Mounting DAX partition.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Mounting DAX partition. Vcb: %1!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 504 — DAX volume mounted without DAX support because storage is not DAX capable.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DAX volume mounted without DAX support because storage is not DAX capable. Vcb: %1!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 505 — NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Mft AttributeList not found, skipping growth.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGrowMftsAttributeListAllocation Vcb:%1!p!, IC:%2!p! Mft AttributeList not found, skipping growth

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64

Event ID 506 — NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Converting Resident AttributeList.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGrowMftsAttributeListAllocation Vcb:%1!p!, IC:%2!p! Converting Resident AttributeList(size:0x%3!I64x!) to NonResident

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_AttrListAllocationSize HexInt64 → HexInt64

Event ID 507 — NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext, AttrListScb:A12_Scb Added Allocation for NonResident AttributeList.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGrowMftsAttributeListAllocation Vcb:%1!p!, IC:%2!p!, AttrListScb:%3!p! Added Allocation for NonResident AttributeList (old size:0x%4!I64x!)

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Scb Pointer → HexInt64
A13_AttrListAllocationSize HexInt64 → HexInt64

Event ID 508 — Unexpected exception code of 0xA10_ExceptionCode received.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Unexpected exception code of 0x%1!x! received

Fields #

NameDescription
A10_ExceptionCode HexInt32 → HexInt32

Event ID 509 — Exception code of 0xA10_ExceptionCode received during mount.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Exception code of 0x%1!x! received during mount.

Fields #

NameDescription
A10_ExceptionCode HexInt32 → HexInt32

Event ID 510 — Unexpected exception code of 0xA10_ExceptionCode received.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Unexpected exception code of 0x%1!x! received.

Fields #

NameDescription
A10_ExceptionCode HexInt32 → HexInt32

Event ID 511 — LogFileFull A10_IrpContext->LogFullReason BackTrace: ln A11_BackTrace[0]; ln A12_BackTrace[1]; ln A13_BackTrace[2]; ln A14_BackTrace[3]; ln A15_BackTrace[4]; ln A16_BackTrace[5]; ln A17_BackTrace[6...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

LogFileFull %1 BackTrace: ln %2!p!; ln %3!p!; ln %4!p!; ln %5!p!; ln %6!p!; ln %7!p!; ln %8!p!; ln %9!p!; ln %10!p!; ln %11!p!; ln %12!p!; ln %13!p!; ln %14!p!; ln %15!p!; ln %16!p!; ln %17!p!; ln %18!p!; ln %19!p!; ln %20!p!; ln %21!p!;

Fields #

NameDescription
A10_IrpContext->LogFullReason UInt32 → unsignedInt
A11_BackTrace[0] Pointer → HexInt64
A12_BackTrace[1] Pointer → HexInt64
A13_BackTrace[2] Pointer → HexInt64
A14_BackTrace[3] Pointer → HexInt64
A15_BackTrace[4] Pointer → HexInt64
A16_BackTrace[5] Pointer → HexInt64
A17_BackTrace[6] Pointer → HexInt64
A18_BackTrace[7] Pointer → HexInt64
A19_BackTrace[8] Pointer → HexInt64
A20_BackTrace[9] Pointer → HexInt64
A21_BackTrace[10] Pointer → HexInt64
A22_BackTrace[11] Pointer → HexInt64
A23_BackTrace[12] Pointer → HexInt64
A24_BackTrace[13] Pointer → HexInt64
A25_BackTrace[14] Pointer → HexInt64
A26_BackTrace[15] Pointer → HexInt64
A27_BackTrace[16] Pointer → HexInt64
A28_BackTrace[17] Pointer → HexInt64
A29_BackTrace[18] Pointer → HexInt64
A30_BackTrace[19] Pointer → HexInt64

Event ID 512 — Unexpected raise of 0xA10_ExceptionCode during critical non-raise code.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Unexpected raise of 0x%1!x! during critical non-raise code

Fields #

NameDescription
A10_ExceptionCode HexInt32 → HexInt32

Event ID 513 — NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsProcessException IC: %1!p!, ExceptionCode: 0x%2!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_ExceptionCode HexInt32 → HexInt32

Event ID 514 — NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsProcessException IC: %1!p!, ExceptionCode: 0x%2!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_ExceptionCode HexInt32 → HexInt32

Event ID 515 — Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContext->Vcb, Count A13_NtfsFailedAborts, Status A14_GetExceptionCode().

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Failed to abort - IrpContext %1!p!, Irp %2!p!, Vcb %3!p!, Count %4!x!, Status %5!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Irp Pointer → HexInt64
A12_IrpContext->Vcb Pointer → HexInt64
A13_NtfsFailedAborts HexInt32 → HexInt32
A14_GetExceptionCode() HexInt32 → HexInt32

Event ID 516 — Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContext->Vcb, Scb A13_NextScb, FileRef A14_*(PULONGLONG)_NextScb->Fcb->FileReference!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Failed to abort - IrpContext %1!p!, Irp %2!p!, Vcb %3!p!, Scb %4!p!, FileRef %5!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Irp Pointer → HexInt64
A12_IrpContext->Vcb Pointer → HexInt64
A13_NextScb Pointer → HexInt64
A14_*(PULONGLONG)_NextScb->Fcb->FileReference HexInt64 → HexInt64

Event ID 517 — Setting STATUS_CANT_WAIT in top-level exception status for write @ 0xA10_IrpSp->Parameters.Write.ByteOffset.HighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Setting STATUS_CANT_WAIT in top-level exception status for write @ 0x%1!08x!%2!08x!

Fields #

NameDescription
A10_IrpSp->Parameters.Write.ByteOffset.HighPart HexInt32 → HexInt32
A11_IrpSp->Parameters.Write.ByteOffset.LowPart HexInt32 → HexInt32

Event ID 518 — Setting 0xA10_ExceptionCode in top-level exception status for write @ 0xA11_IrpSp->Parameters.Write.ByteOffset.HighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Setting 0x%1!x! in top-level exception status for write @ 0x%2!08x!%3!08x!

Fields #

NameDescription
A10_ExceptionCode HexInt32 → HexInt32
A11_IrpSp->Parameters.Write.ByteOffset.HighPart HexInt32 → HexInt32
A12_IrpSp->Parameters.Write.ByteOffset.LowPart HexInt32 → HexInt32

Event ID 519 — [A10_IrpSp->MajorFunction, A11_IrpSp->MinorFunction!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

[%1, %2!02x!]: Irp: %3!p!, IC: %4!p!, Status: %5!S!

Fields #

NameDescription
A10_IrpSp->MajorFunction UInt32 → unsignedInt
A11_IrpSp->MinorFunction HexInt32 → HexInt32
A12_Irp Pointer → HexInt64
A13_IrpContext Pointer → HexInt64
A14_Status HexInt32 → NTStatus

Event ID 520 — [A10_IrpSp->MajorFunction, A11_IrpSp->MinorFunction!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

[%1, %2!02x!]: Irp: %3!p!, IC: %4!p!, Status: %5!S!

Fields #

NameDescription
A10_IrpSp->MajorFunction UInt32 → unsignedInt
A11_IrpSp->MinorFunction HexInt32 → HexInt32
A12_Irp Pointer → HexInt64
A13_IrpContext Pointer → HexInt64
A14_Status HexInt32 → NTStatus

Event ID 521 — Can't handle invalid bitmap in a positive way.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Can't handle invalid bitmap in a positive way.

Event ID 522 — NTFS ETW tracing is now active.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NTFS ETW tracing is now active.

Event ID 523 — Updating NtfsMinTrimTotalSize to A10_MinTrimTotalSize.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Updating NtfsMinTrimTotalSize to %1!x!.

Fields #

NameDescription
A10_MinTrimTotalSize HexInt32 → HexInt32

Event ID 524 — Updating NtfsMaxTrimTotalSize to A10_MaxTrimTotalSize.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Updating NtfsMaxTrimTotalSize to %1!x!.

Fields #

NameDescription
A10_MaxTrimTotalSize HexInt32 → HexInt32

Event ID 525 — NtfsSetObjectId: Caller does not have restore access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetObjectId: Caller does not have restore access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!, Irp Minor Function: 0x%9!08x!.

Event ID 526 — NtfsSetObjectIdExtendedInfo: Caller does not have write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetObjectIdExtendedInfo: Caller does not have write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!, Irp Minor Function: 0x%9!08x!.

Event ID 527 — NtfsDeleteObjectId: Caller does not have write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeleteObjectId: Caller does not have write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!, Irp Minor Function: 0x%9!08x!.

Event ID 528 — A10___FUNCTION__: Setting RM at 0xA11_(PVOID)Vcb->TxfVcb.DefaultRm ({A12__Vcb->TxfVcb.DefaultRm->RmId}) up for auto-restart.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Setting RM at 0x%2!p! ({%3!S!}) up for auto-restart.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)Vcb->TxfVcb.DefaultRm Pointer → HexInt64
A12__Vcb->TxfVcb.DefaultRm->RmId GUID → GUID

Event ID 529 — NtfsFsQuotaSetInfo: Denying access due to administrator limit.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsFsQuotaSetInfo: Denying access due to administrator limit. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!.

Event ID 530 — NtfsCommonSetQuota: Caller does not have manage volume privilege and it's not quota file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonSetQuota: Caller does not have manage volume privilege and it's not quota file. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: 0x%7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!, Ccb Flags: 0x%10!08x!.

Event ID 531 — Unexpected Paging-Read on DAX mappable stream, Scb=A10_Scb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Unexpected Paging-Read on DAX mappable stream, Scb=%1!p!

Fields #

NameDescription
A10_Scb Pointer → HexInt64

Event ID 532 — NtfsSetReparsePoint: Caller does not have write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetReparsePoint: Caller does not have write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb Access flags: 0x%8!08x!, File Object Write Access: %9!d!.

Event ID 533 — NtfsSetReparsePointEx: Caller does not have write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetReparsePointEx: Caller does not have write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb Access flags: 0x%8!08x!, File Object Write Access: %9!d!.

Event ID 534 — NtfsDeleteReparsePoint: Caller does not have write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeleteReparsePoint: Caller does not have write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb Access flags: 0x%8!08x!, File Object Write Access: %9!d!.

Event ID 535 — NtfsAbortTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAbortTransaction IC: %1!p!, TransactionId: 0x%2!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->TransactionId HexInt32 → HexInt32

Event ID 536 — NtfsAbortTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsAbortTransaction IC: %1!p!, TransactionId: 0x%2!08x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->TransactionId HexInt32 → HexInt32

Event ID 537 — DoAction::InitializeFRS IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DoAction::InitializeFRS IC:%1!p!, FileRef:0x%2!04x!_%3!08x!, BaseFRS:0x%4!012I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64

Event ID 538 — DoAction::DeallocateFRS IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DoAction::DeallocateFRS IC:%1!p!, FileRef:0x%2!04x!_%3!08x!, BaseFRS:0x%4!012I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64

Event ID 539 — DoAction::WriteEndOfFRS IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DoAction::WriteEndOfFRS IC:%1!p!, FileRef:0x%2!04x!_%3!08x!, BaseFRS:0x%4!012I64x!, Attrib:0x%5!x! Off:0x%6!x!, Len:0x%7!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64
A14_Attribute->TypeCode HexInt32 → HexInt32
A15_LogRecord->RecordOffset HexInt32 → HexInt32
A16_Length HexInt32 → HexInt32

Event ID 540 — DoAction::CreateAttribute IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DoAction::CreateAttribute IC:%1!p!, FileRef:0x%2!04x!_%3!08x!, BaseFRS:0x%4!012I64x!, Attrib:0x%5!x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64
A14_((PATTRIBUTE_RECORD_HEADER)Data)->TypeCode HexInt32 → HexInt32

Event ID 541 — NtfsRestartChangeValue IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestartChangeValue IC:%1!p!, FileRef:0x%2!04x!_%3!08x!, BaseFRS:0x%4!012I64x!, FileRef:0x%5!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64
A14_NtfsFullSegmentNumber( _FileReference ) HexInt64 → HexInt64

Event ID 542 — DoAction::SetNewAttributeSizes IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DoAction::SetNewAttributeSizes IC:%1!p!, FileRef:0x%2!04x!_%3!08x!, BaseFRS:0x%4!012I64x! OLD: Alloc:%5!I64x!, FileSize:%6!I64x!, VDL:%7!I64x!, TotalAlloc:%8!I64x! NEW: Alloc:%9!I64x!, FileSize:%10!I64x!, VDL:%11!I64x!, TotalAlloc:%12!I64x!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64
A14_Attribute->Form.Nonresident.AllocatedLength HexInt64 → HexInt64
A15_Attribute->Form.Nonresident.FileSize HexInt64 → HexInt64
A16_Attribute->Form.Nonresident.ValidDataLength HexInt64 → HexInt64
A17_Attribute->Form.Nonresident.TotalAllocated HexInt64 → HexInt64
A18_Sizes->AllocationSize HexInt64 → HexInt64
A19_Sizes->FileSize HexInt64 → HexInt64
A20_Sizes->ValidDataLength HexInt64 → HexInt64
A21_Sizes->TotalAllocated HexInt64 → HexInt64

Event ID 543 — DoAction(SetBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12__Bitmap.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DoAction(SetBitsInNonresidentBitMap) IC: %1!p!, Vcb: %2!p!, Bitmap: %3!p!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12__Bitmap Pointer → HexInt64

Event ID 544 — DoAction(ClearBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12__Bitmap.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

DoAction(ClearBitsInNonresidentBitMap) IC: %1!p!, Vcb: %2!p!, Bitmap: %3!p!

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Vcb Pointer → HexInt64
A12__Bitmap Pointer → HexInt64

Event ID 545 — NtfsUpgradeFileSecurity: Denying access due to volume does not support Txf.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsUpgradeFileSecurity: Denying access due to volume does not support Txf. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!.

Event ID 546 — NtfsCaseSensitiveInfoAccessCheck: Caller does not have write access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCaseSensitiveInfoAccessCheck: Caller does not have write access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb Access flags: 0x%8!08x!.

Event ID 547 — NtfsCaseSensitiveInfoAccessCheck: Caller does not have appropriate access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCaseSensitiveInfoAccessCheck: Caller does not have appropriate access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!.

Event ID 548 — NtfsCheckFileForDelete: Denying access due to there are same-tx handles open to this file.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Denying access due to there are same-tx handles open to this file. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Txf Writers Count: %7!d!.

Event ID 549 — NtfsCheckFileForDelete: Denying access due to TxfCheckForLockConflict failed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Denying access due to TxfCheckForLockConflict failed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Original status: %7!S!.

Event ID 550 — NtfsCheckFileForDelete: Denying access due to superseding view indexes are not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Denying access due to superseding view indexes are not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, File Attributes: 0x%7!08x!.

Event ID 551 — NtfsCheckFileForDelete: Denying access due to non-posix delete of target directory open is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Denying access due to non-posix delete of target directory open is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, File Attributes: 0x%7!08x!.

Event ID 552 — NtfsCheckFileForDelete: Denying access due to file is not deleteable.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Denying access due to file is not deleteable. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!.

Event ID 553 — NtfsCheckFileForDelete: Denying access due to target file is read only.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Denying access due to target file is read only. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, File Attributes: 0x%7!08x!, IrpSp->Flags: 0x%8!08x!.

Event ID 554 — NtfsCheckFileForDelete: Caller does not have write attributes access (TxfAccessCheck failed).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Caller does not have write attributes access (TxfAccessCheck failed). Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb AccessFlags: 0x%7!08x!, TxfAccessCheck access status: %8!S!.

Event ID 555 — NtfsCheckFileForDelete: Denying access due to failing to remove image section.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCheckFileForDelete: Denying access due to failing to remove image section. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Scb: %7!p!, AttributeTypeCode: 0x%8!x!, Attribute Name: %9!S!.

Event ID 556 — NtfsGlobalSdUpdate: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGlobalSdUpdate: Caller does not have manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 557 — NtfsRepairItem: Denying access due to volume is locked.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRepairItem: Denying access due to volume is locked. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, VcbState: 0x%5!08x!.

Event ID 558 — NtfsSetRepairState: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetRepairState: Caller does not have manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 559 — NtfsInitiateRepair: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsInitiateRepair: Caller does not have manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 560 — NTFS ETW tracing is shutting down.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NTFS ETW tracing is shutting down.

Event ID 561 — NtfsDefineStorageReserve: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDefineStorageReserve: Caller does not have manage volume privilege. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 562 — NtfsDeleteStorageReserve: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeleteStorageReserve: Caller does not have manage volume privilege. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 563 — NtfsRepairStorageReserve: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRepairStorageReserve: Caller does not have manage volume privilege. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 564 — NtfsSetStorageReserveIdInfo: System files are not allowed to be part of a storage reserve.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetStorageReserveIdInfo: System files are not allowed to be part of a storage reserve. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Fcb State: 0x%7!08x!, Ccb FullFileName: %8!S!.

Event ID 565 — NtfsSetStorageReserveIdInfo: Caller does not have appropriate access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsSetStorageReserveIdInfo: Caller does not have appropriate access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 566 — NtfsChangeStorageReserveId: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsChangeStorageReserveId: Caller does not have manage volume privilege. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!, Operation flags: 0x%9!08x!.

Event ID 567 — NtfsChangeStorageReserveId: Caller does not have manage volume privilege to explicitly setting reserve ID to/from a "restricted area".

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsChangeStorageReserveId: Caller does not have manage volume privilege to explicitly setting reserve ID to/from a "restricted area". Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 568 — Failed to get a non-volatile token for Vcb: A10_Vcb, Status: A11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Failed to get a non-volatile token for Vcb: %1!p!, Status: %2!S!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Status HexInt32 → NTStatus

Event ID 569 — Failed to free non-volatile token for Vcb: A10_Vcb, Status: A11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Failed to free non-volatile token for Vcb: %1!p!, Status: %2!S!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_Status HexInt32 → NTStatus

Event ID 570 — NtfsRestoreScbSnapshots: Restored TotalAllocated, Scb: A10_Scb, TotalAllocated: 0xA11_Scb->TotalAllocated!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestoreScbSnapshots: Restored TotalAllocated, Scb: %1!p!, TotalAllocated: 0x%2!I64x!

Fields #

NameDescription
A10_Scb Pointer → HexInt64
A11_Scb->TotalAllocated HexInt64 → HexInt64

Event ID 571 — NtfsGetDeallocatedClusters: Lsn updated for DeallocatedClusters: A10_CurrentClusters, Lsn: A11_CurrentClusters->Lsn.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsGetDeallocatedClusters: Lsn updated for DeallocatedClusters: %1!p!, Lsn: %2!I64x!

Fields #

NameDescription
A10_CurrentClusters Pointer → HexInt64
A11_CurrentClusters->Lsn.QuadPart HexInt64 → HexInt64

Event ID 572 — ClustersLinkAsHead: A10_ClustersLinkAsHead, FlagsToMatch: 0xA11_FlagsToMatch, InsertAfter: A12_InsertAfter.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

ClustersLinkAsHead: %1!p!, FlagsToMatch: 0x%2!x!, InsertAfter: %3!S!

Fields #

NameDescription
A10_ClustersLinkAsHead Pointer → HexInt64
A11_FlagsToMatch HexInt32 → HexInt32
A12_InsertAfter UInt32 → unsignedInt

Event ID 573 — Clusters: A10_Clusters, Flags: 0xA11_Clusters->Flags.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Clusters: %1!p!, Flags: 0x%2!x!

Fields #

NameDescription
A10_Clusters Pointer → HexInt64
A11_Clusters->Flags HexInt32 → HexInt32

Event ID 574 — Matching cluster: A10_Clusters, NumberOfRuns: 0xA11_NumberOfRuns.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Matching cluster: %1!p!, NumberOfRuns: 0x%2!x!

Fields #

NameDescription
A10_Clusters Pointer → HexInt64
A11_NumberOfRuns HexInt32 → HexInt32

Event ID 575 — Clusters: A10_Clusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Clusters: %1!p!

Fields #

NameDescription
A10_Clusters Pointer → HexInt64

Event ID 576 — Allocated new deallocated clusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Allocated new deallocated clusters

Event ID 577 — Need to add Range.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Need to add Range. DanglingMdl: %1, DeallocatedClusters: %2!p!, Lcn: %3!I64x!, ClusterCount: %4!I64x!

Fields #

NameDescription
A10_!FlagOn( Clusters->Flags, DEALLOCATED_CLUSTERS_FLAG_NO_DANGLING_MDL ) UInt32 → unsignedInt
A11_Clusters Pointer → HexInt64
A12_Lcn HexInt64 → HexInt64
A13_ClusterCount HexInt64 → HexInt64

Event ID 578 — Added range.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Added range. DanglingMdl: %1, DeallocatedClusters: %2!p!, Lcn: %3!I64x!, ClusterCount: %4!I64x!

Fields #

NameDescription
A10_!FlagOn( Clusters->Flags, DEALLOCATED_CLUSTERS_FLAG_NO_DANGLING_MDL ) UInt32 → unsignedInt
A11_Clusters Pointer → HexInt64
A12_Lcn HexInt64 → HexInt64
A13_ClusterCount HexInt64 → HexInt64

Event ID 579 — TxfCheckForLockConflict: File locked for modify transaction.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfCheckForLockConflict: File locked for modify transaction. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!,Fcb: %5!p!, FileRef: 0x%6!I64x!, TxfFcb Flags: 0x%7!08x!, ShareMode: 0x%8!08x!.

Event ID 580 — TxfCheckForLockConflict: Locking transaction is doomed and caller is non-trans or different trans who wants to modify.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfCheckForLockConflict: Locking transaction is doomed and caller is non-trans or different trans who wants to modify. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Granted Access: 0x%7!08x!.

Event ID 581 — TxfCheckForLockConflict: Modification access desired.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfCheckForLockConflict: Modification access desired. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Granted Access: 0x%7!08x!.

Event ID 582 — TxfCheckForLockConflict: File has user handle opened on one of the versions or user-mapping on a section.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfCheckForLockConflict: File has user handle opened on one of the versions or user-mapping on a section. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Granted Access: 0x%7!08x!, Reader cleanup count: %8!d!.

Event ID 583 — A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId}, Tx at 0xA16_(PVOID)TxfTrans {A17__TxfTrans->KtmUow}, Status was 0xA1...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: from %2!S! (%3!S!:%4!d!) RM at 0x%5!p! {%6!S!}, Tx at 0x%7!p! {%8!S!}, Status was 0x%9!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_CallerFunction AnsiString → string
A12_CallerFile AnsiString → string
A13_CallerLineNumber Int32 → int
A14_(PVOID)TxfRmcb Pointer → HexInt64
A15__TxfRmcb->RmId GUID → GUID
A16_(PVOID)TxfTrans Pointer → HexInt64
A17__TxfTrans->KtmUow GUID → GUID
A18_AbortReasonStatus HexInt32 → HexInt32

Event ID 584 — A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId}, Tx at 0xA16_(PVOID)TxfTrans {A17__TxfTrans->KtmUow}, Status was 0xA1...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: from %2!S! (%3!S!:%4!d!) RM at 0x%5!p! {%6!S!}, Tx at 0x%7!p! {%8!S!}, Status was 0x%9!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_CallerFunction AnsiString → string
A12_CallerFile AnsiString → string
A13_CallerLineNumber Int32 → int
A14_(PVOID)TxfRmcb Pointer → HexInt64
A15__TxfRmcb->RmId GUID → GUID
A16_(PVOID)TxfTrans Pointer → HexInt64
A17__TxfTrans->KtmUow GUID → GUID
A18_Status HexInt32 → HexInt32

Event ID 585 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} aborting transaction at 0x%4!p! {%5!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_TxfTrans Pointer → HexInt64
A14__TxfTrans->KtmUow GUID → GUID

Event ID 586 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} aborting transaction at 0x%4!p! {%5!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_TxfTrans Pointer → HexInt64
A14__TxfTrans->KtmUow GUID → GUID

Event ID 587 — A10___FUNCTION__: RM at 0xA11_(PVOID)CalloutParameters->TxfFlush.TxfRmcb {A12__CalloutParameters->TxfFlush.TxfRmcb->RmId}: Unexpected exception code of 0xA13_GetExceptionCode() received.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!}: Unexpected exception code of 0x%4!x! received.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)CalloutParameters->TxfFlush.TxfRmcb Pointer → HexInt64
A12__CalloutParameters->TxfFlush.TxfRmcb->RmId GUID → GUID
A13_GetExceptionCode() HexInt32 → HexInt32

Event ID 588 — A10___FUNCTION__: TxfStartRm reports RM will be reset: RM metadata corrupt.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: RM metadata corrupt

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string

Event ID 589 — A10___FUNCTION__: TxfStartRm reports RM will be reset: TM could not be initialized.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: TM could not be initialized

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string

Event ID 590 — A10___FUNCTION__: TxfStartRm reports RM will be reset: RM log corrupt.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: RM log corrupt

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string

Event ID 591 — A10___FUNCTION__: TxfStartRm reports RM will be reset: log version changed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: log version changed

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string

Event ID 592 — A10___FUNCTION__: TxfStartRm reports RM will be reset: dedicated log found, need multiplexed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: dedicated log found, need multiplexed

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string

Event ID 593 — A10___FUNCTION__: TxfStartRm reports RM will be reset: multiplexed log found, need dedicated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: multiplexed log found, need dedicated

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string

Event ID 594 — A10___FUNCTION__: TxfStartRm reports RM will be reset: CLFS log metadata corrupt.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: CLFS log metadata corrupt

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string

Event ID 595 — A10___FUNCTION__: TxfStartRm reports RM will be reset: 0xA11_FailureStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxfStartRm reports RM will be reset: 0x%2!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_FailureStatus HexInt32 → HexInt32

Event ID 596 — A10___FUNCTION__: RM did not start and WILL NOT be reset, status code is 0xA11_FailureStatus!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM did not start and WILL NOT be reset, status code is 0x%2!x!!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_FailureStatus HexInt32 → HexInt32

Event ID 597 — A10___FUNCTION__: Could not initialize IrpContext: 0xA11_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Could not initialize IrpContext: 0x%2!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_Status HexInt32 → HexInt32

Event ID 598 — TxfInitializeVolume: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfInitializeVolume: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown). Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, FxfVcb flags: 0x%5!08x!.

Event ID 599 — A10___FUNCTION__: IOCTL_VOLUME_GET_GPT_ATTRIBUTES returned 0xA11_TempStatus for default RM on VCB at 0xA12_(PVOID)Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: IOCTL_VOLUME_GET_GPT_ATTRIBUTES returned 0x%2!x! for default RM on VCB at 0x%3!p!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_TempStatus HexInt32 → HexInt32
A12_(PVOID)Vcb Pointer → HexInt64

Event ID 600 — A10___FUNCTION__: Exception code 0xA11_GetExceptionCode(), Status 0xA12_Status for default RM on VCB at 0xA13_(PVOID)Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Exception code 0x%2!x!, Status 0x%3!x! for default RM on VCB at 0x%4!p!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_GetExceptionCode() HexInt32 → HexInt32
A12_Status HexInt32 → HexInt32
A13_(PVOID)Vcb Pointer → HexInt64

Event ID 601 — A10___FUNCTION__: Couldn't reset default RM on VCB at 0xA11_(PVOID)Vcb after A12_TXF_MAX_RESET_ATTEMPTS_ON_MOUNT tries: 0xA13_OldStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Couldn't reset default RM on VCB at 0x%2!p! after %3!d! tries: 0x%4!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)Vcb Pointer → HexInt64
A12_TXF_MAX_RESET_ATTEMPTS_ON_MOUNT Int32 → int
A13_OldStatus HexInt32 → HexInt32

Event ID 602 — A10___FUNCTION__: Exception 0xA11_GetExceptionCode() raised from TxfConvertRmStartFailureStatusCode for default RM on VCB at 0xA12_(PVOID)Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Exception 0x%2!x! raised from TxfConvertRmStartFailureStatusCode for default RM on VCB at 0x%3!p!.  RM will NOT be reset.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_GetExceptionCode() HexInt32 → HexInt32
A12_(PVOID)Vcb Pointer → HexInt64

Event ID 603 — A10___FUNCTION__: A11_(NT_SUCCESS( Status ) ? 'Succeeded' : 'FAILED') auto-restart of RM at 0xA12_(PVOID)TxfRmcb ({A13__TxfRmcb->RmId}): 0xA14_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: %2!S! auto-restart of RM at 0x%3!p! ({%4!S!}): 0x%5!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(NT_SUCCESS( Status ) ? 'Succeeded' : 'FAILED') AnsiString → string
A12_(PVOID)TxfRmcb Pointer → HexInt64
A13__TxfRmcb->RmId GUID → GUID
A14_Status HexInt32 → HexInt32

Event ID 604 — A10___FUNCTION__: Attempting auto-restart of RM at 0xA11_(PVOID)TxfRmcb ({A12__TxfRmcb->RmId}).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Attempting auto-restart of RM at 0x%2!p! ({%3!S!})

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 605 — A10___FUNCTION__: Volume too small to start RM at 0xA11_(PVOID)TxfRmcb ({A12__TxfRmcb->RmId}).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Volume too small to start RM at 0x%2!p! ({%3!S!})

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 606 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: invalid flags in $Tops.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: invalid flags in $Tops

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 607 — TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown). Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, FxfVcb flags: 0x%5!08x!.

Event ID 608 — A10___FUNCTION__: Raising to reset RM at 0xA11_(PVOID)TxfRmcb ({A12__TxfRmcb->RmId}): Explicit reset requested.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Raising to reset RM at 0x%2!p! ({%3!S!}): Explicit reset requested

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 609 — TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown). Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, FxfVcb flags: 0x%5!08x!.

Event ID 610 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: no TXF_DATA in root.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: no TXF_DATA in root

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 611 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Different nesting levels of 0xA13_LogNestingLevel and 0xA14_DiskNestingLevel.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!}: Different nesting levels of 0x%4!x! and 0x%5!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_LogNestingLevel HexInt32 → HexInt32
A14_DiskNestingLevel HexInt32 → HexInt32

Event ID 612 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: restart area already exists.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: restart area already exists

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 613 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: restart area already exists.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: restart area already exists

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 614 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: RmID in restart area does not match {A13__ClfsRestartArea->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: RmID in restart area does not match {%4!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13__ClfsRestartArea->RmId GUID → GUID

Event ID 615 — A10___FUNCTION__: Got A11_Status from ClfsGetLogFileInformation for RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Got %2!d! from ClfsGetLogFileInformation for RM at 0x%3!p! {%4!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_Status Int32 → int
A12_(PVOID)TxfRmcb Pointer → HexInt64
A13__TxfRmcb->RmId GUID → GUID

Event ID 616 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Restart LSN is before beginning of log.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Restart LSN is before beginning of log.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 617 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: MinRollforwardEndLsn is beyond end of log.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: MinRollforwardEndLsn is beyond end of log.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 618 — A10___FUNCTION__: TxF RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} started successfully.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxF RM at 0x%2!p! {%3!S!} started successfully.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 619 — A10___FUNCTION__: TxF RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} failed to start with Status 0xA13_Status A14_AbnormalTermination() ? '(abnormal termination)' : ''.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: TxF RM at 0x%2!p! {%3!S!} failed to start with Status 0x%4!x! %5!S!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_Status HexInt32 → HexInt32
A14_AbnormalTermination() ? '(abnormal termination)' : '' AnsiString → string

Event ID 620 — A10___FUNCTION__: Shutting down A11_(TxfIsDefaultRm( TxfRmcb ) ? 'default' : 'secondary') RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Shutting down %2!S! RM at 0x%3!p! {%4!S!}.  Shutdown is %5!S!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(TxfIsDefaultRm( TxfRmcb ) ? 'default' : 'secondary') AnsiString → string
A12_(PVOID)TxfRmcb Pointer → HexInt64
A13__TxfRmcb->RmId GUID → GUID
A14_(ForceDirtyShutdown ? 'DIRTY!' : 'CLEAN.') AnsiString → string

Event ID 621 — A10___FUNCTION__: Setting RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} up for auto-restart.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Setting RM at 0x%2!p! {%3!S!} up for auto-restart.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 622 — TxfFlushAndInvalidateExistingStructures: File has open user handles.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfFlushAndInvalidateExistingStructures: File has open user handles. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, CleanupCount: %7!d!.

Event ID 623 — (A10_FILEID_FROM_SOURCE( FileNLine ):A11_LINENUM_FROM_SOURCE( FileNLine )) - TXF_HARD_ERROR on RM at 0xA12_TxfRmcb ({A13__TxfRmcb->RmId}): A14_Status).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

(%1:%2!d!) - TXF_HARD_ERROR on RM at 0x%3!p! ({%4!S!}): %5!S!)

Fields #

NameDescription
A10_FILEID_FROM_SOURCE( FileNLine ) UInt32 → unsignedInt
A11_LINENUM_FROM_SOURCE( FileNLine ) Int32 → int
A12_TxfRmcb Pointer → HexInt64
A13__TxfRmcb->RmId GUID → GUID
A14_Status HexInt32 → NTStatus

Event ID 624 — A10___FUNCTION__: Renamed RM at 0xA11_(PVOID)TxfRmcb from {A12__OldGuid} to {A13__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Renamed RM at 0x%2!p! from {%3!S!} to {%4!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__OldGuid GUID → GUID
A13__TxfRmcb->RmId GUID → GUID

Event ID 625 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}, rolling back Tx at 0xA13_(PVOID)TxfTrans {A14__TxfTrans->KtmUow}, Status was 0xA15_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!}, rolling back Tx at 0x%4!p! {%5!S!}, Status was 0x%6!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_(PVOID)TxfTrans Pointer → HexInt64
A14__TxfTrans->KtmUow GUID → GUID
A15_Status HexInt32 → HexInt32

Event ID 626 — A10___FUNCTION__: Renamed RM at 0xA11_(PVOID)TxfRmcb from {A12__OldGuid} to {A13__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Renamed RM at 0x%2!p! from {%3!S!} to {%4!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__OldGuid GUID → GUID
A13__TxfRmcb->RmId GUID → GUID

Event ID 627 — TxfFsctlStartRm: Denying access due starting default RM is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfFsctlStartRm: Denying access due starting default RM is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, RmRootFcb: %5!p!.

Event ID 628 — TxfFsctlWriteBackupInformation: Denying access due RM is active.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfFsctlWriteBackupInformation: Denying access due RM is active. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, BackupInfo flags: 0x%5!08x!.

Event ID 629 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found too high of a TxF ID in log.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Found too high of a TxF ID in log

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 630 — A10___FUNCTION__: Error Setting Delete Disposition: 0xA11_Status FileObject: 0xA12_(PVOID)FileObject.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Error Setting Delete Disposition: 0x%2!x!  FileObject: 0x%3!p!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_Status HexInt32 → HexInt32
A12_(PVOID)FileObject Pointer → HexInt64

Event ID 631 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Got a RECOVER notification for a transaction that isn't in-doubt.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Got a RECOVER notification for a transaction that isn't in-doubt

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 632 — TxfSetupTransactionContextFromCcb: Modifying operation is now allowed with a non-TxF modify handle.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfSetupTransactionContextFromCcb: Modifying operation is now allowed with a non-TxF modify handle. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Scb: %7!p!, Attribute Type Code: 0x%8!x!, Ccb FullFileName: %9!S!, Ccb flags: 0x%10!08x!.

Event ID 633 — TxfSetupTransactionContextFromCcb: Invalid TxF structure.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfSetupTransactionContextFromCcb: Invalid TxF structure. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Scb: %7!p!, TxfFo: %8!p!, KtmTrans: %9!p!, TxfRmcb: %10!p!, Ccb FullFileName: %11!S!

Event ID 634 — TxfSetupTransactionContextFromCcb: Denying access of modifying operation on a read-only handle.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TxfSetupTransactionContextFromCcb: Denying access of modifying operation on a read-only handle. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Scb: %7!p!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!, FO write access: %10!d!, FO delete access: %11!d!.

Event ID 635 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} raising 0xA13_ExceptionCode to KTM!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} raising 0x%4!x! to KTM!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_ExceptionCode HexInt32 → HexInt32

Event ID 636 — A10___FUNCTION__: Commit (0xA11_TransactionNotification) ofA12_(TransactionAlreadyPrepared ? ' **PREPARED** ' : ' ')tx {A13__TxfTrans->KtmUow} on RM at 0xA14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId} fai...

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Commit (0x%2!x!) of%3!S!tx {%4!S!} on RM at 0x%5!p! {%6!S!} failed with 0x%7!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_TransactionNotification HexInt32 → HexInt32
A12_(TransactionAlreadyPrepared ? ' **PREPARED** ' : ' ') AnsiString → string
A13__TxfTrans->KtmUow GUID → GUID
A14_(PVOID)TxfRmcb Pointer → HexInt64
A15__TxfRmcb->RmId GUID → GUID
A16_Status HexInt32 → HexInt32

Event ID 637 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow} (notify commit).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} aborting transaction at 0x%4!p! {%5!S!} (notify commit)

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_TxfTrans Pointer → HexInt64
A14__TxfTrans->KtmUow GUID → GUID

Event ID 638 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow} (notify rollback).

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} aborting transaction at 0x%4!p! {%5!S!} (notify rollback)

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_TxfTrans Pointer → HexInt64
A14__TxfTrans->KtmUow GUID → GUID

Event ID 639 — A10___FUNCTION__: Error doing IRP_MJ_FLUSH_BUFFERS on RM at 0xA11_(PVOID)Trans->TxfRmcb {A12__Trans->TxfRmcb->RmId}: 0xA13_FlushStatus.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Error doing IRP_MJ_FLUSH_BUFFERS on RM at 0x%2!p! {%3!S!}: 0x%4!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)Trans->TxfRmcb Pointer → HexInt64
A12__Trans->TxfRmcb->RmId GUID → GUID
A13_FlushStatus HexInt32 → HexInt32

Event ID 640 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} trying to abort transaction at 0xA13_Trans {A14__Trans->KtmUow}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} trying to abort transaction at 0x%4!p! {%5!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_Trans Pointer → HexInt64
A14__Trans->KtmUow GUID → GUID

Event ID 641 — A10___FUNCTION__: Aborting call stack: 0xA11_CallStack[0] 0xA12_CallStack[1] 0xA13_CallStack[2] 0xA14_CallStack[3] 0xA15_CallStack[4].

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Aborting call stack: 0x%2!p! 0x%3!p! 0x%4!p! 0x%5!p! 0x%6!p!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_CallStack[0] Pointer → HexInt64
A12_CallStack[1] Pointer → HexInt64
A13_CallStack[2] Pointer → HexInt64
A14_CallStack[3] Pointer → HexInt64
A15_CallStack[4] Pointer → HexInt64

Event ID 642 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_Trans {A14__Trans->KtmUow}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} aborting transaction at 0x%4!p! {%5!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_Trans Pointer → HexInt64
A14__Trans->KtmUow GUID → GUID

Event ID 643 — A10___FUNCTION__: 0xA11_Status initializing IrpContext for tx at A12_(PVOID)Trans {A13__Trans->KtmUow}, RM at A14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: 0x%2!x! initializing IrpContext for tx at %3!p! {%4!S!}, RM at %5!p! {%6!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_Status HexInt32 → HexInt32
A12_(PVOID)Trans Pointer → HexInt64
A13__Trans->KtmUow GUID → GUID
A14_(PVOID)TxfRmcb Pointer → HexInt64
A15__TxfRmcb->RmId GUID → GUID

Event ID 644 — A10___FUNCTION__: 0xA11_Status writing log record for RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}, Tx at 0xA14_(PVOID)Trans {A15__Trans->KtmUow}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: 0x%2!x! writing log record for RM at 0x%3!p! {%4!S!}, Tx at 0x%5!p! {%6!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_Status HexInt32 → HexInt32
A12_(PVOID)TxfRmcb Pointer → HexInt64
A13__TxfRmcb->RmId GUID → GUID
A14_(PVOID)Trans Pointer → HexInt64
A15__Trans->KtmUow GUID → GUID

Event ID 645 — A10___FUNCTION__: About to force aborts on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: About to force aborts on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 646 — A10___FUNCTION__: BaseLsn is greater than TargetLsn on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: BaseLsn is greater than TargetLsn on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 647 — A10___FUNCTION__: No transactions remain on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: No transactions remain on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 648 — A10___FUNCTION__: Transaction's first undo LSN greater than TargetLsn on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Transaction's first undo LSN greater than TargetLsn on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 649 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} surprise-aborting transaction at 0xA13_OldestTrans {A14__OldestTrans->KtmUow}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} surprise-aborting transaction at 0x%4!p! {%5!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_OldestTrans Pointer → HexInt64
A14__OldestTrans->KtmUow GUID → GUID

Event ID 650 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} got 0xA13_Status from TxfTryAbortTransaction on Tx 0xA14_OldestTrans {A15__OldestTrans->KtmUow}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!} got 0x%4!x! from TxfTryAbortTransaction on Tx 0x%5!p! {%6!S!}

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_Status HexInt32 → HexInt32
A14_OldestTrans Pointer → HexInt64
A15__OldestTrans->KtmUow GUID → GUID

Event ID 651 — A10___FUNCTION__: Inactive RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Inactive RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 652 — A10___FUNCTION__: Log is pinned on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Log is pinned on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 653 — A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}, rolling back KTM Tx at 0xA13_(PVOID)TransToDereference {A14__TransToDereference->KtmUow}, Status was 0xA15_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: RM at 0x%2!p! {%3!S!}, rolling back KTM Tx at 0x%4!p! {%5!S!}, Status was 0x%6!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_(PVOID)TransToDereference Pointer → HexInt64
A14__TransToDereference->KtmUow GUID → GUID
A15_Status HexInt32 → HexInt32

Event ID 654 — A10___FUNCTION__: Log pinned trying to advance RestartLsn on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Log pinned trying to advance RestartLsn on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 655 — A10___FUNCTION__: Log pinned by doomed transaction on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Log pinned by doomed transaction on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 656 — A10___FUNCTION__: Reporting 0xA11_PinnedStatus to CLFS from RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}: 0xA14_Status.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Reporting 0x%2!X! to CLFS from RM at 0x%3!p! {%4!S!}: 0x%5!x!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_PinnedStatus HexInt32 → HexInt32
A12_(PVOID)TxfRmcb Pointer → HexInt64
A13__TxfRmcb->RmId GUID → GUID
A14_Status HexInt32 → HexInt32

Event ID 657 — A10___FUNCTION__: Done forcing aborts on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Done forcing aborts on RM at 0x%2!p! {%3!S!}.

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 658 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Txf directory is missing in pre-existing RM.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: $Txf directory is missing in pre-existing RM

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 659 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found $Txf without DUP_INDEX_IS_DOLLAR_TXF_DIRECTORY.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Found $Txf without DUP_INDEX_IS_DOLLAR_TXF_DIRECTORY

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 660 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found non-empty $Txf but there is no log.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Found non-empty $Txf but there is no log

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 661 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find $INDEX_ROOT on $Txf.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Couldn't find $INDEX_ROOT on $Txf

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 662 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find TXF_DATA_ATTR on $Txf.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Couldn't find TXF_DATA_ATTR on $Txf

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 663 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found TXF_DATA_ATTR for normal file on $Txf.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Found TXF_DATA_ATTR for normal file on $Txf

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 664 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Expected a secondary RM here.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Expected a secondary RM here

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 665 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is missing but $Txf is non-empty.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: $Tops is missing but $Txf is non-empty

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 666 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is missing but there is already a log.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: $Tops is missing but there is already a log

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 667 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is A13_(IsEncrypted( _TopsFcb->Info ) ? 'encrypted' : 'compressed').

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: $Tops is %4!S!

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID
A13_(IsEncrypted( _TopsFcb->Info ) ? 'encrypted' : 'compressed') AnsiString → string

Event ID 668 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Missing $STANDARD_INFORMATION.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Missing $STANDARD_INFORMATION

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 669 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find file attributes.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Couldn't find file attributes

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 670 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is corrupt.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: $Tops is corrupt

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 671 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Could not find unnamed data stream.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Could not find unnamed data stream

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 672 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops metadata is the wrong version or records wrong size.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: $Tops metadata is the wrong version or records wrong size

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 673 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops metadata is the wrong size.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: $Tops metadata is the wrong size

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 674 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Non-NULL RM ID found in $Tops and there is no log.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Non-NULL RM ID found in $Tops and there is no log

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 675 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Epoch in $Tops metadata doesn't match RM.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Epoch in $Tops metadata doesn't match RM

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 676 — A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find $T stream.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

%1: Corrupt RM at 0x%2!p! {%3!S!}: Couldn't find $T stream

Fields #

NameDescription
A10___FUNCTION__ AnsiString → string
A11_(PVOID)TxfRmcb Pointer → HexInt64
A12__TxfRmcb->RmId GUID → GUID

Event ID 677 — NtfsReadUsnJournal: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsReadUsnJournal: Caller does not have manage volume privilege. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 678 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Decided to trim usn journal.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TrimUsnJournal (%1!p!, %2!p!): Decided to trim usn journal.  FirstValidUsn %3!I64x!, new FirstValidUsn %4!I64x!, FS %5!I64x!, AS %6!I64x!, MaxSize %7!I64x!, DeltaSize %8!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_Vcb->FirstValidUsn HexInt64 → HexInt64
A13_FirstValidUsn HexInt64 → HexInt64
A14_TrackUsnJournalFileSize HexInt64 → HexInt64
A15_TrackUsnJournalAllocationSize HexInt64 → HexInt64
A16_TrackUsnJournalMaxSize HexInt64 → HexInt64
A17_TrackUsnJournalDeltaAllocation HexInt64 → HexInt64

Event ID 679 — TrimUsnJournal (A10_Vcb, A11_IrpContext): About to delete allocation till A12_FirstValidUsn - 1!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TrimUsnJournal (%1!p!, %2!p!): About to delete allocation till %3!I64x!, SavedReserve %4!I64x!, RequiredReserve %5!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_FirstValidUsn - 1 HexInt64 → HexInt64
A13_SavedReserved HexInt64 → HexInt64
A14_RequiredReserved HexInt64 → HexInt64

Event ID 680 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Before trimming journal AS A12_UsnJournal->Header.AllocationSize.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TrimUsnJournal (%1!p!, %2!p!): Before trimming journal AS %3!I64x!, FS %4!I64x!, VDL %5!I64x!, TA %6!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_UsnJournal->Header.AllocationSize.QuadPart HexInt64 → HexInt64
A13_UsnJournal->Header.FileSize.QuadPart HexInt64 → HexInt64
A14_UsnJournal->Header.ValidDataLength.QuadPart HexInt64 → HexInt64
A15_UsnJournal->TotalAllocated HexInt64 → HexInt64

Event ID 681 — TrimUsnJournal (A10_Vcb, A11_IrpContext): After trimming journal AS A12_UsnJournal->Header.AllocationSize.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TrimUsnJournal (%1!p!, %2!p!): After trimming journal AS %3!I64x!, FS %4!I64x!, VDL %5!I64x!, TA %6!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_UsnJournal->Header.AllocationSize.QuadPart HexInt64 → HexInt64
A13_UsnJournal->Header.FileSize.QuadPart HexInt64 → HexInt64
A14_UsnJournal->Header.ValidDataLength.QuadPart HexInt64 → HexInt64
A15_UsnJournal->TotalAllocated HexInt64 → HexInt64

Event ID 682 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Mapping pairs validated.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TrimUsnJournal (%1!p!, %2!p!): Mapping pairs validated

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64

Event ID 683 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Checkpointed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

TrimUsnJournal (%1!p!, %2!p!): Checkpointed

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64

Event ID 684 — NtfsQueryUsnJournal: Denying access due to NULL Ccb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsQueryUsnJournal: Denying access due to NULL Ccb. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!.

Event ID 685 — NtfsDeleteUsnJournal: Caller does not have manage volume access.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsDeleteUsnJournal: Caller does not have manage volume access. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: %6!I64x!, Ccb FullFileName: %7!S!, Ccb access flags: 0x%8!08x!.

Event ID 686 — NtfsRestartUsnJournal: Caller does not have manage volume privilege.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsRestartUsnJournal: Caller does not have manage volume privilege. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, Ccb FullFileName: %8!S!, Ccb access flags: 0x%9!08x!.

Event ID 687 — NtOfsCreateAttributeEx: Stream already has a open user handle.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtOfsCreateAttributeEx: Stream already has a open user handle. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, Fcb: %5!p!, FileRef: 0x%6!I64x!, Scb: %7!p!, Scb Type Code: 0x%8!x!, Scb Name: %9!S!, Scb CleanupCount: %10!d!.

Event ID 688 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContext->OriginatingIrp,A13_PsGetCurrentThread()): Extending journal from AS A14_Scb->Header.AllocationSize.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

OfsSetLength (%1!p!,%2!p!,%3!p!,%4!p!): Extending journal from AS %5!I64x!, FS %6!I64x!, VDL %7!I64x!, to AS %8!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_IrpContext->OriginatingIrp Pointer → HexInt64
A13_PsGetCurrentThread() Pointer → HexInt64
A14_Scb->Header.AllocationSize.QuadPart HexInt64 → HexInt64
A15_Scb->Header.FileSize.QuadPart HexInt64 → HexInt64
A16_Scb->Header.ValidDataLength.QuadPart HexInt64 → HexInt64
A17_NewAllocationSize HexInt64 → HexInt64

Event ID 689 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContext->OriginatingIrp,A13_PsGetCurrentThread()): Done extending journal AS A14_Scb->Header.AllocationSize.QuadPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

OfsSetLength (%1!p!,%2!p!,%3!p!,%4!p!): Done extending journal AS %5!I64x!, FS %6!I64x!, VDL %7!I64x!, TA %8!I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_IrpContext->OriginatingIrp Pointer → HexInt64
A13_PsGetCurrentThread() Pointer → HexInt64
A14_Scb->Header.AllocationSize.QuadPart HexInt64 → HexInt64
A15_Scb->Header.FileSize.QuadPart HexInt64 → HexInt64
A16_Scb->Header.ValidDataLength.QuadPart HexInt64 → HexInt64
A17_Scb->TotalAllocated HexInt64 → HexInt64

Event ID 690 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContext->OriginatingIrp,A13_PsGetCurrentThread()): After NtfsWriteFileSizes.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

OfsSetLength (%1!p!,%2!p!,%3!p!,%4!p!): After NtfsWriteFileSizes

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_IrpContext->OriginatingIrp Pointer → HexInt64
A13_PsGetCurrentThread() Pointer → HexInt64

Event ID 691 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContext->OriginatingIrp,A13_PsGetCurrentThread()): After NtfsSetCcFileSizesUsnBiasAware.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

OfsSetLength (%1!p!,%2!p!,%3!p!,%4!p!): After NtfsSetCcFileSizesUsnBiasAware

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_IrpContext Pointer → HexInt64
A12_IrpContext->OriginatingIrp Pointer → HexInt64
A13_PsGetCurrentThread() Pointer → HexInt64

Event ID 692 — NtOfsPostNewLength (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Status A13_IrpContext->ExceptionStatus before calling NtfsReadUsnJournal.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtOfsPostNewLength (%1!p!,%2!p!,%3!p!): Status %4!x! before calling NtfsReadUsnJournal

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_IrpContext->OriginatingIrp Pointer → HexInt64
A12_PsGetCurrentThread() Pointer → HexInt64
A13_IrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 693 — NtfsIsRegionDangling: RemainingClusterCount: 0xA10_RemainingClusterCount!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsIsRegionDangling: RemainingClusterCount: 0x%1!I64x!, Scb: %2!p!, Vcn: 0x%3!I64x!, Lcn: 0x%4!I64x!, Clusters: 0x%5!I64x!

Fields #

NameDescription
A10_RemainingClusterCount HexInt64 → HexInt64
A11_Scb Pointer → HexInt64
A12_Vcn HexInt64 → HexInt64
A13_Lcn HexInt64 → HexInt64
A14_ClusterCount HexInt64 → HexInt64

Event ID 694 — Vcb A10_Vcb - has *no* active PFNs.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p! - has *no* active PFNs

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 695 — Vcb A10_Vcb - failed to query active PFNs assuming there are some.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p! - failed to query active PFNs assuming there are some

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 696 — Vcb A10_Vcb - has active PFNs.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Vcb %1!p! - has active PFNs

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 697 — NtfsPerformDismountOnVcb: Vcb A10_Vcb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPerformDismountOnVcb: Vcb %1!p!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 698 — NtfsPerformDismountOnVcb: Vcb A10_Vcb - Found frozen deallocated clusters.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPerformDismountOnVcb: Vcb %1!p! - Found frozen deallocated clusters

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 699 — NtfsPerformDismountOnVcb: Vcb A10_Vcb - Wait for any on going trim to finish.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPerformDismountOnVcb: Vcb %1!p! - Wait for any on going trim to finish

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 700 — NtfsPerformDismountOnVcb: Vcb A10_Vcb - No more on going trim.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPerformDismountOnVcb: Vcb %1!p! - No more on going trim

Fields #

NameDescription
A10_Vcb Pointer → HexInt64

Event ID 701 — NtfsPerformDismountOnVcb: IC: %1, Vcb: %2, Label: %3, DeviceName: %4.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPerformDismountOnVcb: IC: %1!p!, Vcb: %2!p!, Label: %3!S!, DeviceName: %4!S!

Event ID 702 — NtfsPostVcbIsCorrupt.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPostVcbIsCorrupt(%1!p!, %2!x!, %3!p!, %4!p!, %5!016I64x!): IrpContext->TopLevelIrpContext->ExceptionStatus == %6!x! before NtfsSetVcbDirtyFlag.

Fields #

NameDescription
A10_IrpContext Pointer → HexInt64
A11_Status HexInt32 → HexInt32
A12_FileReference Pointer → HexInt64
A13_Fcb Pointer → HexInt64
A14_Source HexInt64 → HexInt64
A15_TopLevelExceptionStatus HexInt32 → HexInt32

Event ID 703 — NtfsPostVcbIsCorrupt: Marking volume dirty.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsPostVcbIsCorrupt: Marking volume dirty.  Vcb %1!p!, WasDirty: %2!x!, FileReference %3!I64x!, Source %4!016I64x!

Fields #

NameDescription
A10_Vcb Pointer → HexInt64
A11_WasDirty HexInt32 → HexInt32
A12_NtfsFullSegmentNumber( _BugCheckFileReference ) HexInt64 → HexInt64
A13_Source HexInt64 → HexInt64

Event ID 704 — NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for IndexOpen of \$Extend\$Quota with FileFsControlInformation.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for IndexOpen of \$Extend\$Quota with FileFsControlInformation. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, FsInformationClass: 0x%8!x!, Scb: %9!p!.

Event ID 705 — NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for IndexOpen of \$Extend\$Quota with FileFsControlInformation.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for IndexOpen of \$Extend\$Quota with FileFsControlInformation. Thread: %1!p!, TypeOfOpen: %2!d!, Vcb: %3!p!, VolumeName: %4!S!, VolumeLabel: %5!S!, Fcb: %6!p!, FileRef: %7!I64x!, FsInformationClass: 0x%8!x!, Scb: %9!p!.

Event ID 706 — Succeeding log write @ 0xA10_IrpSp->Parameters.Write.ByteOffset.HighPart!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Succeeding log write @ 0x%1!08x!%2!08x! after getting 0x%3!x! in top-level irpcontext

Fields #

NameDescription
A10_IrpSp->Parameters.Write.ByteOffset.HighPart HexInt32 → HexInt32
A11_IrpSp->Parameters.Write.ByteOffset.LowPart HexInt32 → HexInt32
A12_IrpContext->TopLevelIrpContext->ExceptionStatus HexInt32 → HexInt32

Event ID 707 — Unexpected Paging-Write on stream accessed in Direct-Access mode, Scb=A10_Scb.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Unexpected Paging-Write on stream accessed in Direct-Access mode, Scb=%1!p!

Fields #

NameDescription
A10_Scb Pointer → HexInt64

Event ID 708 — NtfsCommonWrite: Writing beyond highest writable sector on active volume is not allowed.

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

NtfsCommonWrite: Writing beyond highest writable sector on active volume is not allowed. Thread: %1!p!, Vcb: %2!p!, VolumeName: %3!S!, VolumeLabel: %4!S!, RequestedRange: 0x%5!I64x!, AllowedRange: 0x%6!I64x!.

Event ID 709 — Ignoring write to 0xA10_StartingVbo!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Ignoring write to 0x%1!I64x!, SCB length is 0x%2!I64x! for SCB 0x%3!Ix!

Fields #

NameDescription
A10_StartingVbo HexInt64 → HexInt64
A11_Scb->Header.ValidDataLength.QuadPart HexInt64 → HexInt64
A12_(ptrdiff_t) Scb Pointer → HexInt64

Event ID 710 — Truncating write from 0xA10_ByteRange!

Provider
Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Channel
Operational

Message #

Truncating write from 0x%1!I64x! to 0x%2!I64x! for SCB 0x%3!Ix!

Fields #

NameDescription
A10_ByteRange HexInt64 → HexInt64
A11_SectorAlignedVdl HexInt64 → HexInt64
A12_(ptrdiff_t) Scb Pointer → HexInt64