Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355

708 events across 1 channel

Event IDTitleChannel
10Operational
11Operational
12Operational
13Operational
14Operational
15Operational
16Operational
17Operational
18Operational
19Operational
20Operational
21Operational
22Operational
23Operational
24Operational
25Operational
26Operational
27Operational
28Operational
29Operational
30Operational
31Operational
32Operational
33Operational
34Operational
35Operational
36Operational
37Operational
38Operational
39Operational
40Operational
41Operational
42Operational
43Operational
44Operational
45Operational
46Operational
47Operational
48Operational
49Operational
50Operational
51Operational
52Operational
53Operational
54Operational
55Operational
56Operational
57Operational
58Operational
59Operational
60Operational
61Operational
62Operational
63Operational
64Operational
65Operational
66Operational
67Operational
68Operational
69Operational
70Operational
71Operational
72Operational
73Operational
74Operational
75Operational
76Operational
77Operational
78Operational
79Operational
80Operational
81Operational
82Operational
83Operational
84Operational
85Operational
86Operational
87Operational
88Operational
89Operational
90Operational
91Operational
92Operational
93Operational
94Operational
95Operational
96Operational
97Operational
98Operational
99Operational
100Operational
101Operational
102Operational
103Operational
104Operational
105Operational
106Operational
107Operational
108Operational
109Operational
110Operational
111Operational
112Operational
113Operational
114Operational
115Operational
116Operational
117Operational
118Operational
119Operational
120Operational
121Operational
122Operational
123Operational
124Operational
125Operational
126Operational
127Operational
128Operational
129Operational
130Operational
131Operational
132Operational
133Operational
134Operational
135Operational
136Operational
137Operational
138Operational
139Operational
140Operational
141Operational
142Operational
143Operational
144Operational
145Operational
146Operational
147Operational
148Operational
149Operational
150Operational
151Operational
152Operational
153Operational
154Operational
155Operational
156Operational
157Operational
158Operational
159Operational
160Operational
161Operational
162Operational
163Operational
164Operational
165Operational
166Operational
167Operational
168Operational
169Operational
170Operational
171Operational
172Operational
173Operational
174Operational
175Operational
176Operational
177Operational
178Operational
179Operational
180Operational
181Operational
182Operational
183Operational
184Operational
185Operational
186Operational
187Operational
188Operational
189Operational
190Operational
191Operational
192Operational
193Operational
194Operational
195Operational
196Operational
197Operational
198Operational
199Operational
200Operational
201Operational
202Operational
203Operational
204Operational
205Operational
206Operational
207Operational
208Operational
209Operational
210Operational
211Operational
212Operational
213Operational
214Operational
215Operational
216Operational
217Operational
218Operational
219Operational
220Operational
221Operational
222Operational
223Operational
224Operational
225Operational
226Operational
227Operational
228Operational
229Operational
230Operational
231Operational
232Operational
233Operational
234Operational
235Operational
236Operational
237Operational
238Operational
239Operational
240Operational
241Operational
242Operational
243Operational
244Operational
245Operational
246Operational
247Operational
248Operational
249Operational
250Operational
251Operational
252Operational
253Operational
254Operational
255Operational
256Operational
257Operational
258Operational
259Operational
260Operational
261Operational
262Operational
263Operational
264Operational
265Operational
266Operational
267Operational
268Operational
269Operational
270Operational
271Operational
272Operational
273Operational
274Operational
275Operational
276Operational
277Operational
278Operational
279Operational
280Operational
281Operational
282Operational
283Operational
284Operational
285Operational
286Operational
287Operational
288Operational
289Operational
290Operational
291Operational
292Operational
293Operational
294Operational
295Operational
296Operational
297Operational
298Operational
299Operational
300Operational
301Operational
302Operational
303Operational
304Operational
305Operational
306Operational
307Operational
308Operational
309Operational
310Operational
311Operational
312Operational
313Operational
314Operational
315Operational
316Operational
317Operational
318Operational
319Operational
320Operational
321Operational
322Operational
323Operational
324Operational
325Operational
326Operational
327Operational
328Operational
329Operational
330Operational
331Operational
332Operational
333Operational
334Operational
335Operational
336Operational
337Operational
338Operational
339Operational
340Operational
341Operational
342Operational
343Operational
344Operational
345Operational
346Operational
347Operational
348Operational
349Operational
350Operational
351Operational
352Operational
353Operational
354Operational
355Operational
356Operational
357Operational
358Operational
359Operational
360Operational
361Operational
362Operational
363Operational
364Operational
365Operational
366Operational
367Operational
368Operational
369Operational
370Operational
371Operational
372Operational
373Operational
374Operational
375Operational
376Operational
377Operational
378Operational
379Operational
380Operational
381Operational
382Operational
383Operational
384Operational
385Operational
386Operational
387Operational
388Operational
389Operational
390Operational
391Operational
392Operational
393Operational
394Operational
395Operational
396Operational
397Operational
398Operational
399Operational
400Operational
401Operational
402Operational
403Operational
404Operational
405Operational
406Operational
407Operational
408Operational
409Operational
410Operational
411Operational
412Operational
413Operational
414Operational
415Operational
416Operational
417Operational
418Operational
419Operational
420Operational
421Operational
422Operational
423Operational
424Operational
425Operational
426Operational
427Operational
428Operational
429Operational
430Operational
431Operational
432Operational
433Operational
434Operational
435Operational
436Operational
437Operational
438Operational
439Operational
440Operational
441Operational
442Operational
443Operational
444Operational
445Operational
446Operational
447Operational
448Operational
449Operational
450Operational
451Operational
452Operational
453Operational
454Operational
455Operational
456Operational
457Operational
458Operational
459Operational
460Operational
461Operational
462Operational
463Operational
464Operational
465Operational
466Operational
467Operational
468Operational
469Operational
470Operational
471Operational
472Operational
473Operational
474Operational
475Operational
476Operational
477Operational
478Operational
479Operational
480Operational
481Operational
482Operational
483Operational
484Operational
485Operational
486Operational
487Operational
488Operational
489Operational
490Operational
491Operational
492Operational
493Operational
494Operational
495Operational
496Operational
497Operational
498Operational
499Operational
500Operational
501Operational
502Operational
503Operational
504Operational
505Operational
506Operational
507Operational
508Operational
509Operational
510Operational
511Operational
512Operational
513Operational
514Operational
515Operational
516Operational
517Operational
518Operational
519Operational
520Operational
521Operational
522Operational
523Operational
524Operational
525Operational
526Operational
527Operational
528Operational
529Operational
530Operational
531Operational
532Operational
533Operational
534Operational
535Operational
536Operational
537Operational
538Operational
539Operational
540Operational
541Operational
542Operational
543Operational
544Operational
545Operational
546Operational
547Operational
548Operational
549Operational
550Operational
551Operational
552Operational
553Operational
554Operational
555Operational
556Operational
557Operational
558Operational
559Operational
560Operational
561Operational
562Operational
563Operational
564Operational
565Operational
566Operational
567Operational
568Operational
569Operational
570Operational
571Operational
572Operational
573Operational
574Operational
575Operational
576Operational
577Operational
578Operational
579Operational
580Operational
581Operational
582Operational
583Operational
584Operational
585Operational
586Operational
587Operational
588Operational
589Operational
590Operational
591Operational
592Operational
593Operational
594Operational
595Operational
596Operational
597Operational
598Operational
599Operational
600Operational
601Operational
602Operational
603Operational
604Operational
605Operational
606Operational
607Operational
608Operational
609Operational
610Operational
611Operational
612Operational
613Operational
614Operational
615Operational
616Operational
617Operational
618Operational
619Operational
620Operational
621Operational
622Operational
623Operational
624Operational
625Operational
626Operational
627Operational
628Operational
629Operational
630Operational
631Operational
632Operational
633Operational
634Operational
635Operational
636Operational
637Operational
638Operational
639Operational
640Operational
641Operational
642Operational
643Operational
644Operational
645Operational
646Operational
647Operational
648Operational
649Operational
650Operational
651Operational
652Operational
653Operational
654Operational
655Operational
656Operational
657Operational
658Operational
659Operational
660Operational
661Operational
662Operational
663Operational
664Operational
665Operational
666Operational
667Operational
668Operational
669Operational
670Operational
671Operational
672Operational
673Operational
674Operational
675Operational
676Operational
677Operational
678Operational
679Operational
680Operational
681Operational
682Operational
683Operational
684Operational
685Operational
686Operational
687Operational
688Operational
689Operational
690Operational
691Operational
692Operational
693Operational
694Operational
695Operational
696Operational
697Operational
698Operational
699Operational
700Operational
701Operational
702Operational
703Operational
704Operational
705Operational
706Operational
707Operational
708Operational
709Operational
710Operational
711Operational
712Operational
713Operational
714Operational
715Operational
716Operational
717Operational

Event ID 10 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcn
A11_AttributeFormNonresidentLowestVcn
A12_AttributeFormNonresidentHighestVcn
A13_AllocationClusters

Event ID 11 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Scb

Event ID 12 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FileObject
A11_Scb
A12_StartingVcn
A13_ClusterCount
A14_Flags
A15_CcbForWriteExtend

Event ID 13 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_FileObject
A12_Scb
A13_StartingVcn
A14_ClusterCount
A15_Flags
A16_CcbForWriteExtend

Event ID 14 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_PurgeOffset

Event ID 15 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_PurgeOffset
A12_PurgeChunkLength

Event ID 16 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_LastVcn
A12_AttributeInstance

Event ID 17 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_NtfsFullFileRefNumber_FcbFileReference

Event ID 18 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_NtfsFullFileRefNumber_FcbFileReference

Event ID 19 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_ValueLength
A12_AttributeFlags

Event ID 20 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_LastVcn
A15_NewHighestVcn
A16_PassCount

Event ID 21 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn
A16_ContextAttributeListEntryLowestVcn

Event ID 22 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn
A16_ContextAttributeListEntryLowestVcn

Event ID 23 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn
A16_ContextAttributeListEntryLowestVcn
A17_PassCount

Event ID 24 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn
A16_ContextAttributeListEntryLowestVcn

Event ID 25 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NtfsFrsConsolidationStatisticsMergeSkipCount

Event ID 26 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FileRecordSegmentNumberHighPart
A11_FileRecordSegmentNumberLowPart
A12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment
A13_AttributeTypeCode

Event ID 27 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FileRecordSegmentNumberHighPart
A11_FileRecordSegmentNumberLowPart
A12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment
A13_AttributeTypeCode

Event ID 28 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FcbVcb
A11_IrpContext
A12_PULONGLONG_FcbFileReference
A13_StdInfoAttrListEntrySignature
A14_StdInfoAttrListEntryLastCompactedSize
A15_CurrentAttributeListSize

Event ID 29 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FcbVcb
A11_IrpContext
A12_PULONGLONG_FcbFileReference
A13_StdInfoAttrListEntrySignature
A14_StdInfoAttrListEntryLastCompactedSize
A15_NewStdInfoAttrListEntryLastCompactedSize

Event ID 30 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_i
A12_MAX_MOVEABLE_ATTRIBUTES
A13_AttributeTypeCode
A14_AttributeRecordLength
A15_AttributeInstance

Event ID 31 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_SizeNeeded
A12_AttributeTypeCode
A13_AttributeRecordLength
A14_AttributeFormCode
A15_AttributeInstance

Event ID 32 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_SizeNeeded
A12_BytesToFree
A13_MappingPairSize
A14_NewMappingPairSize

Event ID 33 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FileRecordSegmentNumberHighPart
A11_FileRecordSegmentNumberLowPart
A12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment
A13_StartZero
A14_ZeroLength

Event ID 34 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ScbAttributeTypeCode
A15__ScbAttributeName
A16_NewStartVcn
A17_NewHalfWayVcn
A18_NewFinalVcn
A19_PackedMode
A20_TryPrior

Event ID 35 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ScbAttributeTypeCode
A15__ScbAttributeName
A16_FileRecordSequenceNumber
A17_FileRecordSegmentNumberLowPart
A18_NewStartVcn
A19_LastVcn
A20_NewFinalVcn

Event ID 36 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ScbAttributeTypeCode
A15__ScbAttributeName
A16_FileRecordSequenceNumber
A17_FileRecordSegmentNumberLowPart
A18_NewStartVcn
A19_LastVcn
A20_NewFinalVcn

Event ID 37 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NewFinalVcn

Event ID 38 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NewHalfWayVcn
A15_RangePtr

Event ID 39 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NewHalfWayVcn
A15_RangePtr

Event ID 40 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NtfsMcbArray
A15_NtfsMcbArrayStartingVcn
A16_NtfsMcbArrayEndingVcn

Event ID 41 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NtfsMcbArray
A15_NtfsMcbArrayStartingVcn
A16_NtfsMcbArrayEndingVcn

Event ID 42 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NtfsMcbArray
A15_NtfsMcbArrayStartingVcn
A16_NtfsMcbArrayEndingVcn

Event ID 43 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NtfsMcbArray
A15_NtfsMcbArrayStartingVcn
A16_NtfsMcbArrayEndingVcn

Event ID 44 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NewFinalVcnInMcb
A15_NewFinalVcn

Event ID 45 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NewStartVcn
A15_LastVcn
A16_NewFinalVcn
A17_NewFinalVcnInMcb
A18_NumberOfRanges
A19_DeletedNextAttribute
A20_Mcb1StartWithNewStartVcn
A21_Mcb1HoldNewStartVcn
A22_Mcb2StartWithNewStartVcn
A23_Mcb2HoldNewStartVcn
A24_McbArraySizeInUseChange

Event ID 46 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_NewStartVcn
A15_DeletedNextAttributeNewFinalVcnInMcbLastVcn1

Event ID 47 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_LastVcn
A15_NewFinalVcnInMcb

Event ID 48 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ScbAttributeTypeCode
A15__ScbAttributeName
A16_PULONGLONG_ContextAttributeListEntrySegmentReference
A17_OldLowestVcn
A18_StartVcn
A19_NewAttributeInstance

Event ID 49 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_IrpContext
A12_Scb
A13_PULONGLONG_ScbFcbFileReference
A14_ScbAttributeTypeCode
A15__ScbAttributeName
A16_OldLowestVcn
A17_StartVcn
A18_OldHighestVcn
A19_LastVcn
A20_FileRecordSequenceNumber
A21_FileRecordSegmentNumberLowPart

Event ID 50 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread

Event ID 51 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14__VolumeId
A15_VcbVcbState

Event ID 52 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference
A14_AllFlagsFirstRequest

Event ID 53 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference

Event ID 54 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference

Event ID 55 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference
A14_FrsConsolidationContextRestartAttributeTypeCode
A15__FrsConsolidationContextRestartAttributeName
A16_FrsConsolidationContextRestartVcn
A17_FrsConsolidationContextRestartAttributeListEntryOffset
A18_AttributeListEntryOffset
A19_AttrContextAttributeListAttributeListFormNonresidentValidDataLength
A20_AttributeListGrowBy
A21_AttributeListGrowBy

Event ID 56 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference
A14_FrsConsolidationContextRestartAttributeTypeCode
A15__FrsConsolidationContextRestartAttributeName
A16_FrsConsolidationContextRestartVcn
A17_FrsConsolidationContextInstance
A18_FrsConsolidationContextRestartAttributeListEntryOffset
A19_AttrContextAttributeListAttributeListFormNonresidentValidDataLength

Event ID 57 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference
A14_FrsConsolidationContextRestartAttributeTypeCode
A15__FrsConsolidationContextRestartAttributeName
A16_FrsConsolidationContextRestartVcn
A17_FrsConsolidationContextInstance
A18_FrsConsolidationContextRestartAttributeListEntryOffset
A19_AttrContextAttributeListAttributeListFormNonresidentValidDataLength

Event ID 58 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference
A14_Scb

Event ID 59 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference

Event ID 60 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_PULONGLONG_FrsConsolidationContextFileReference
A13_IrpContextExceptionStatus

Event ID 61 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference

Event ID 62 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_PULONGLONG_FcbFileReference

Event ID 63 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_FileRef
A14_ExceptionStatus

Event ID 64 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Fcb
A13_FileRef
A14_RemovedFcb
A15_AllFlagsFcbAcquired
A16_IrpContextTransactionId

Event ID 65 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_EndTimeQuadPart1000NtfsPerformanceFrequencyQuadPart
A13_FrsConsolidationContextTotalTime1000NtfsPerformanceFrequencyQuadPart

Event ID 66 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FcbVcb
A11_IrpContext
A12_PULONGLONG_FcbFileReference
A13_StdInfoAttrListEntrySignature
A14_StdInfoAttrListEntryLastCompactedSize
A15_AttributeListSize

Event ID 67 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_Scb
A13__ScbMcb
A14_OriginalStartingVcn
A15_ClusterCount
A16_AllocateAll
A17_TargetLcnNULLTargetLcnULONGLONG1
A18_PreAllocated
A19_UseDelayedAllocation

Event ID 68 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_Scb
A13__ScbMcb
A14_OriginalStartingVcn
A15_ClusterCount
A16_AllocateAll
A17_TargetLcnNULLTargetLcnULONGLONG1
A18_PreAllocated
A19_UseDelayedAllocation

Event ID 69 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FoundClusterCount
A11_Scb
A12_ScbTotalAllocated

Event ID 70 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FoundClusterCount
A11_Scb
A12_ScbTotalAllocated
A13_ScbState
A14_IrpContextState2
A15_AllocateWithNoHole

Event ID 71 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_ClustersAllocated

Event ID 72 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_ClustersAllocated

Event ID 73 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_Scb
A13__ScbMcb
A14_StartingVcn
A15_EndingVcn

Event ID 74 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PULONGLONG_ScbFcbFileReference
A12_StartingVcn
A13_EndingVcn

Event ID 75 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_Scb
A13__ScbMcb
A14_StartingVcn
A15_EndingVcn

Event ID 76 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PULONGLONG_ScbFcbFileReference
A12_AdjLcn
A13_AdjClusterCount

Event ID 77 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 78 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_DeallocatedClusters
A12_DeallocatedClustersLsnQuadPart
A13_DeallocatedClustersClusterCount
A14_DeallocatedClustersFlags
A15_VcbDeallocatedClusters
A16_VcbDeallocatedClustersAdjClusterCount

Event ID 79 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ClusterCount
A11_Scb
A12_TotalAllocated
A13_TotalAllocated

Event ID 80 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ClusterCount
A11_Scb
A12_TotalAllocated
A13_ScbState
A14_IrpContextState2

Event ID 81 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbDeallocatedClusters
A12_VcbDeallocatedClustersClustersRemoved

Event ID 82 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_ClustersDeallocated

Event ID 83 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_ClustersDeallocated

Event ID 84 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_FirstBit
A13_BeyondFinalBit
A14_RedoOperation
A15_UndoOperation

Event ID 85 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11__Bitmap
A12_BaseLcn
A13_CurrentLcn

Event ID 86 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_StartingLcn
A13_ClusterCount

Event ID 87 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11__Bitmap
A12_BaseLcn
A13_StartingLcn

Event ID 88 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Bitmap
A12_BitMapOffset
A13_NumberOfBits

Event ID 89 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_StartingLcn
A13_ClusterCount

Event ID 90 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11__Bitmap
A12_BaseLcn
A13_StartingLcn

Event ID 91 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Bitmap
A12_BitMapOffset
A13_NumberOfBits

Event ID 92 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_Bitmap
A13_StartingBitmapLcn
A14_SetBits

Event ID 93 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Bitmap
A12_StartingBit
A13_EndingBit

Event ID 94 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Results

Event ID 95 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_i
A11_OriginalSystemBitmapisizeofOriginalSystemBitmap0

Event ID 96 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 97 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Length
A11_BinIndex
A12_Key
A13_BitPosition
A14_GroupIndex
A15_GroupShiftFactor

Event ID 98 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Length
A11_BinIndex
A12_TotalBins

Event ID 99 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_BinIndex
A11_MAXLONGLONG
A12_TotalBins

Event ID 100 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_BinIndex
A11_MaxLength
A12_GroupIndex
A13_RelativeBinIndex
A14_MaxKey

Event ID 101 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_NtfsCachedRunBinGroupShift
A11_NtfsCachedRunBinGroupSize
A12_NtfsCachedRunBinGroupMask

Event ID 102 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_BinIndex
A11_MaxLength
A12_MaxLength

Event ID 103 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_StartingCluster
A11_ClusterCount
A12_VcbTotalClustersCommitted
A13_VcbTotalClusters
A14_VcbFreeClusters

Event ID 104 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_FirstBitToClear
A12_BeyondLastBitToClear1

Event ID 105 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 106 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_FreeClusterBase1
A12_FreeClusterCount1

Event ID 107 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 108 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_FreeClusterBase2
A12_FreeClusterCount2

Event ID 109 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PsGetCurrentThread
A12_VcbTotalClustersCommitted
A13_VcbTotalClusters
A14_VcbTPMapSizeOfBitMap

Event ID 110 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContextMajorFunction

Event ID 111 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingZero
A12_ByteCount
A13_ExtentsDescriptor
A14_ExtentsDescriptorIndex
A15_ExtentsDescriptorStartOffset
A16_Offset
A17_MaxRuns

Event ID 112 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_RunIndex
A11_ExtentsDescriptorRunRunIndexBasePage
A12_ExtentsDescriptorRunRunIndexPageCount
A13_ExtentLength
A14_Offset
A15_RunIndexStartOffset

Event ID 113 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 114 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_LengthInExtent
A11_ByteCount

Event ID 115 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_StartingPhysicalAddrQuadPart
A11_LengthInExtent

Event ID 116 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExtentsDescriptorIndex
A11_ExtentsDescriptorStartOffset

Event ID 117 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingOffset
A12_BeyondEndOffset

Event ID 118 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_DataSetRangeIndex
A11_DsmBufferDataSetRangesDataSetRangeIndexStartingOffset
A12_DsmBufferDataSetRangesDataSetRangeIndexLengthInBytes

Event ID 119 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_RemainingClusterCount
A11_DataSetRangeIndex

Event ID 120 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_DsmByteAddressRangesTotalNumberOfRanges
A11_DsmByteAddressRangesNumberOfRangesReturned

Event ID 121 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Index
A11_DsmByteAddressRangesRangesIndexStartAddress
A12_DsmByteAddressRangesRangesIndexLengthInBytes

Event ID 122 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_StartingPhysicalAddrQuadPart
A11_LengthInExtent

Event ID 123 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExtentsDescriptorIndex
A11_ExtentsDescriptorStartOffset

Event ID 124 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingZero
A12_BeyondEndOffset
A13_ByteCount
A14_ExtentsDescriptor
A15_ExtentsDescriptorIndexExtentsDescriptorIndex0
A16_ExtentsDescriptorStartOffsetExtentsDescriptorStartOffset0

Event ID 125 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExtentsDescriptorIndex
A11_ExtentsDescriptorStartOffset

Event ID 126 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Scb
A12_StartOffset
A13_ByteCount

Event ID 127 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext

Event ID 128 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_TypeOfOpen

Event ID 129 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 130 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 131 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 132 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Irp
A11_IrpContext
A12_Vcb
A13_CreateContextFileObject
A14_CreateContextFileObjectRelatedFileObject
A15__CreateContextFileObjectFileName
A16_CreateContextIrpSpParametersCreateOptions
A17_CreateContextIrpSpParametersCreateFileAttributes
A18_CreateContextDesiredAccess
A19_CreateContextIrpSpParametersCreateShareAccess
A20_CreateContextIrpSpParametersCreateEaLength

Event ID 133 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Irp
A11_IrpContext
A12_Vcb
A13_CreateContextFileObject
A14_CreateContextFileObjectRelatedFileObject
A15__CreateContextFileObjectFileName
A16_CreateContextIrpSpParametersCreateOptions
A17_CreateContextIrpSpParametersCreateFileAttributes
A18_CreateContextDesiredAccess
A19_CreateContextIrpSpParametersCreateShareAccess
A20_CreateContextIrpSpParametersCreateEaLength

Event ID 134 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 135 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_CreateDisposition

Event ID 136 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 137 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_IrpSpParametersCreateShareAccess
A15_ReadULongNoFence_VcbCleanupCount
A16_BiasedCleanupCount

Event ID 138 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 139 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_IrpSpParametersCreateShareAccess
A15_VcbReadOnlyCloseCount
A16_VcbCloseCount
A17_VcbSystemFileCloseCount

Event ID 140 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbCleanupCount
A17_FcbFcbState
A18_IrpSpFlags

Event ID 141 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbFcbState
A17_IrpSpFlags

Event ID 142 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_IrpContextState
A17_IrpSpFlags

Event ID 143 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbFcbState
A17_CreateContextIrpSpParametersCreateOptions24_0x000000ff
A18_CreateContextIrpSpParametersCreateSecurityContextDesiredAccess

Event ID 144 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_CreateContextCurrentFcbVcb
A12__CreateContextCurrentFcbVcbVolumeName
A13_WppCountedStringWCreateContextCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCreateContextCurrentFcbVcbVpb
A14_CreateContextCurrentFcb
A15_NtfsFullFileRefNumber_CreateContextCurrentFcbFileReference
A16_CreateContextCurrentFcbInfoFileAttributes
A17_CreateContextCurrentFcbTxfRmcbRmState

Event ID 145 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_CreateContextCurrentFcbVcb
A12__CreateContextCurrentFcbVcbVolumeName
A13_WppCountedStringWCreateContextCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCreateContextCurrentFcbVcbVpb
A14_CreateContextCurrentFcb
A15_NtfsFullFileRefNumber_CreateContextCurrentFcbFileReference
A16_CreateContextCurrentFcbFcbState
A17_CreateContextIrpSpParametersCreateOptions24_0x000000ff
A18_CreateContextIrpSpParametersCreateSecurityContextDesiredAccess

Event ID 146 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbFcbState

Event ID 147 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbFcbState
A17_CreateContextIrpSpParametersCreateOptions24_0x000000ff
A18_CreateContextIrpSpParametersCreateSecurityContextDesiredAccess

Event ID 148 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbTxfRmcbRmState

Event ID 149 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ParentScbFcbVcb
A12__ParentScbFcbVcbVolumeName
A13_WppCountedStringWParentScbFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHParentScbFcbVcbVpb
A14_ParentScbFcb
A15_NtfsFullFileRefNumber_ParentScbFcbFileReference
A16_ParentScbFcbFcbState
A17_ParentScbFcbTxfRmcbRmState
A18_AttrTypeCode

Event ID 150 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_CreateContextIrpSpParametersCreateOptions
A17_CcbFlags

Event ID 151 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ParentScbVcb
A12__ParentScbVcbVolumeName
A13_WppCountedStringWParentScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHParentScbVcbVpb
A14_ParentScbFcb
A15_NtfsFullFileRefNumber_ParentScbFcbFileReference
A16_ParentScbFcbFcbState
A17_ParentScbFcbTxfRmcbRmState

Event ID 152 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbTxfRmcbRmState

Event ID 153 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisEaInformationNeedEaCount
A17_CreateContextIrpSpParametersCreateOptions
A18_CcbFlags

Event ID 154 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_AttrTypeCode
A17_CreateDisposition

Event ID 155 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_CreateDisposition

Event ID 156 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbFcbState
A17_AttrTypeCode

Event ID 157 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbInfoFileAttributes
A17_FileAttributes

Event ID 158 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_CreateContextIrpSpParametersCreateOptions

Event ID 159 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_CreateContextThisScbAttributeTypeCode
A17_CreateContextThisScbState
A18_CreateContextThisScbScbTypeDataHighWaterMark

Event ID 160 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_AttrCode
A15_CreateDisposition

Event ID 161 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_AttrCode
A15_IrpSpParametersCreateSecurityContextAccessStateOriginalDesiredAccess

Event ID 162 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_AttrCode

Event ID 163 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_ThisScb
A17_ThisScbAttributeTypeCode
A18__ThisScbAttributeName
A19_IrpSpParametersCreateShareAccess
A20_IrpSpParametersCreateSecurityContextAccessStatePreviouslyGrantedAccess

Event ID 164 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_ThisScb
A17_ThisScbAttributeTypeCode
A18__ThisScbAttributeName

Event ID 165 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_ThisScb
A17_ThisScbAttributeTypeCode
A18__ThisScbAttributeName
A19_IrpSpParametersCreateSecurityContextAccessStatePreviouslyGrantedAccess

Event ID 166 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_ThisScb
A17_ThisScbMarkHandleDisallowWritesCount
A18_IrpSpParametersCreateSecurityContextDesiredAccess

Event ID 167 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_ThisScb
A17_ThisScbAttributeTypeCode
A18__ThisScbAttributeName
A19_IrpSpParametersCreateShareAccess
A20_GrantedAccess

Event ID 168 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_IrpSpParametersCreateShareAccess
A17_IrpSpFileObjectFlags

Event ID 169 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_ThisScb
A17_ThisScbAttributeTypeCode
A18__ThisScbAttributeName
A19_IrpSpParametersCreateShareAccess
A20_GrantedAccess

Event ID 170 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_IrpSpParametersCreateShareAccess
A17_IrpSpFileObjectFlags

Event ID 171 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_IrpSpParametersCreateSecurityContextDesiredAccess
A17_ThisFcbInfoFileAttributes
A18_IrpSpFlags

Event ID 172 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_CurrentFcbVcb
A12__CurrentFcbVcbVolumeName
A13_WppCountedStringWCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCurrentFcbVcbVpb
A14_CurrentFcb
A15_NtfsFullFileRefNumber_CurrentFcbFileReference
A16_CurrentFcbInfoFileAttributes
A17_NtfsDataFlags

Event ID 173 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_CurrentFcbVcb
A12__CurrentFcbVcbVolumeName
A13_WppCountedStringWCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCurrentFcbVcbVpb
A14_CurrentFcb
A15_NtfsFullFileRefNumber_CurrentFcbFileReference
A16_CurrentFcbInfoFileAttributes
A17_ThisScbAttributeFlags

Event ID 174 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisScbVcb
A12__ThisScbVcbVolumeName
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb
A14_ThisScbFcb
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference
A16_CreateContextCurrentFcbCleanupCount
A17_NtfsDataEncryptionCallBackTableImplementationFlags

Event ID 175 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_CurrentFcb
A12_NtfsFullFileRefNumber_CurrentFcbFileReference
A13_CurrentFcbTxfRmcbRmState

Event ID 176 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_LcbFcbVcb
A12__LcbFcbVcbVolumeName
A13_WppCountedStringWLcbFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHLcbFcbVcbVpb
A14_LcbFcb
A15_NtfsFullFileRefNumber_LcbFcbFileReference
A16_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength
A17_DesiredAccess
A18_DesiredShareAccess
A19_IoShareAccessFlags
A20_LinkShareAccessOpenCount
A21_LinkShareAccessDeleters
A22_LinkShareAccessSharedDelete

Event ID 177 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_ScbAttributeTypeCode
A17__ScbAttributeName
A18_DesiredAccess
A19_DesiredShareAccess
A20_IoShareAccessFlags
A21_ShareAccessOpenCount
A22_ShareAccessReaders
A23_ShareAccessWriters
A24_ShareAccessDeleters
A25_ShareAccessSharedRead
A26_ShareAccessSharedWrite
A27_ShareAccessSharedDelete

Event ID 178 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_ScbAttributeTypeCode
A17__ScbAttributeName
A18_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength
A19_DesiredAccess
A20_DesiredShareAccess
A21_IoShareAccessFlags
A22_ShareAccessOpenCount
A23_ShareAccessReaders
A24_ShareAccessWriters
A25_ShareAccessDeleters
A26_ShareAccessSharedRead
A27_ShareAccessSharedWrite
A28_ShareAccessSharedDelete
A29_LinkShareAccessOpenCount
A30_LinkShareAccessDeleters
A31_LinkShareAccessSharedDelete

Event ID 179 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_ScbAttributeTypeCode
A17__ScbAttributeName
A18_ARGUMENT_PRESENTLcbWppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLengthWppCountedStringWNULL0
A19_AccessStatePreviouslyGrantedAccess
A20_AccessStateFlags
A21_DesiredShareAccess
A22_CreateDisposition
A23_ScbShareAccessOpenCount
A24_ScbShareAccessReaders
A25_ScbShareAccessWriters
A26_ScbShareAccessDeleters
A27_ScbShareAccessSharedRead
A28_ARGUMENT_PRESENTLcbLcbLinkShareAccessDeleters0

Event ID 180 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FILEID_FROM_SOURCEFileNLine
A11_LINENUM_FROM_SOURCEFileNLine
A12_Status
A13__ProcessName

Event ID 181 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FILEID_FROM_SOURCEFileNLine
A11_LINENUM_FROM_SOURCEFileNLine
A12_Status
A13__ProcessName

Event ID 182 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FILEID_FROM_SOURCEFileNLine
A11_LINENUM_FROM_SOURCEFileNLine
A12_Status
A13__ProcessName

Event ID 183 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FILEID_FROM_SOURCEFileNLine
A11_LINENUM_FROM_SOURCEFileNLine
A12_Status
A13__ProcessName

Event ID 184 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_StartingCluster
A12_RunLength

Event ID 185 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 186 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_MarkUnusedContextDeallocatedClusters
A13__MarkUnusedContextDeallocatedClustersMcb

Event ID 187 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_StartingCluster
A12_RunLength
A13__MarkUnusedContextDeallocatedClustersMcb

Event ID 188 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11__MarkUnusedContextDeallocatedClustersMcb

Event ID 189 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_IrpContext

Event ID 190 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 191 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Src
A11_Dst
A12_SrcClustersCount
A13_SrcDeallocatedClustersClusterCount
A14_SrcDsmAttrDataSetRangesLength

Event ID 192 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Src
A11_Dst
A12_SrcClustersCount
A13_DstClustersCount
A14_DstDsmAttrDataSetRangesLength
A15_DstFirstDataSetRangePtrLengthInBytes
A16_DstFirstDataSetRangePtrStartingOffset

Event ID 193 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 194 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_VcbDeallocatedClusters
A13_VcbDeallocatedClustersListLengthInTrim
A14_VcbDeallocatedClustersListLengthToDrain
A15_ClustersClusterCount
A16_InitialRanges

Event ID 195 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_StartingLcn
A13_ClusterCount
A14_FreeClusterBase1
A15_FreeClusterCount1
A16_FreeClusterBase2
A17_FreeClusterCount2

Event ID 196 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 197 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbCloseCount

Event ID 198 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 199 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Irp

Event ID 200 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext

Event ID 201 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 202 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 203 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 204 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_SmallMarkUnusedContext
A12_MarkUnusedContext

Event ID 205 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext

Event ID 206 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext

Event ID 207 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_TrimEntryCount
A13_DataSetRangePtrStartingOffset
A14_DataSetRangePtrLengthInBytes

Event ID 208 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_IrpUsed

Event ID 209 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_Status

Event ID 210 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext

Event ID 211 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext

Event ID 212 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_Status
A12_MarkUnusedContext
A13_MarkUnusedContextNULL__MarkUnusedContextDeallocatedClustersNULLMarkUnusedContextDeallocatedClustersClusterCount1LL

Event ID 213 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 214 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_DeallocatedClusters

Event ID 215 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_DeallocatedClusters

Event ID 216 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_DeallocatedClusters

Event ID 217 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_All

Event ID 218 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 219 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 220 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 221 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 222 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_DeallocatedClustersToWaitForDeallocatedClusters

Event ID 223 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 224 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContextVcb
A11_DeallocatedClustersToWaitForDeallocatedClusters

Event ID 225 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_WaitInSeconds
A11_CurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartULONGCurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartNtfsDataSystemTimeIncrementINTERVAL_ONE_SECOND0
A12_IrpContext
A13_IrpContextVcb
A14_DeallocatedClusters

Event ID 226 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_WaitInSeconds
A11_CurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartULONGCurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartNtfsDataSystemTimeIncrementINTERVAL_ONE_SECOND0
A12_IrpContext
A13_IrpContextVcb
A14_DeallocatedClusters

Event ID 227 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbDeallocatedClustersListLengthInTrim

Event ID 228 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 229 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 230 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_AcquiredVcb

Event ID 231 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext

Event ID 232 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_RunIndex
A13_StartingOffset
A14_LengthInBytes

Event ID 233 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_DataSetRangeCount
A13_McbRunCount
A14_SmartTrimFreeRangeCount

Event ID 234 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext
A12_RunIndex
A13_DataSetRangeStartingOffset
A14_DataSetRangeLengthInBytes

Event ID 235 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_StartingLcn
A12_ClusterCount
A13_FirstTpMapBit
A14_LastTpMapBit

Event ID 236 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_SmartTrimStateSlabRangesCount

Event ID 237 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_SlabRangeIndex
A12_SlabRangeFirstTPMapBit
A13_SlabRangeLastTPMapBit

Event ID 238 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 239 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 240 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 241 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_AcquiredBitmap

Event ID 242 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_TpMapBit

Event ID 243 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_TpMapBit

Event ID 244 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_TpMapBit
A12_SlabBaseLcn
A13_SlabLengthInClusters

Event ID 245 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 246 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 247 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 248 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState
A15_IrpSpFlags

Event ID 249 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Status

Event ID 250 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 251 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 252 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 253 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScbVcb
A11_StartingVbo
A12_ByteCount

Event ID 254 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FileObject

Event ID 255 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ULONGBadVcn
A11_PLARGE_INTEGER_BadVcnHighPart

Event ID 256 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ULONGBadLcn
A11_PLARGE_INTEGER_BadLcnHighPart

Event ID 257 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 258 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 259 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_NewBufferSize

Event ID 260 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_NewBufferSize
A11_NtfsGetCompressionBufferSize

Event ID 261 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 262 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12_NewBufferSize

Event ID 263 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_NewBufferSize
A11_NtfsGetUsaBufferSizeVcb

Event ID 264 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 265 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbPersist
A20_CcbFlags

Event ID 266 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 267 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 268 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbPersist
A20_CcbFlags

Event ID 269 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_NtfsFullFileRefNumber_ScbFcbFileReference
A14_MoveDataStartingVcnQuadPart
A15_TransferClusters
A16_Lcn
A17_MoveDataStartingLcnQuadPart
A18_CopyLength
A19_FlagsUseDelayedAllocation
A20_Status

Event ID 270 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_NtfsFullFileRefNumber_ScbFcbFileReference
A14_MoveDataStartingVcnQuadPart
A15_TransferClusters
A16_Lcn
A17_MoveDataStartingLcnQuadPart
A18_CopyLength
A19_FlagsUseDelayedAllocation
A20_MyStatus

Event ID 271 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_NtfsFullFileRefNumber_ScbFcbFileReference
A14_Lcn
A15_CopyLength
A16_MyStatus

Event ID 272 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_NtfsFullFileRefNumber_ScbFcbFileReference
A14_MoveDataStartingLcnQuadPart
A15_CopyLength
A16_MyStatus

Event ID 273 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_NtfsFullFileRefNumber_ScbFcbFileReference
A14_MoveDataStartingVcnQuadPart
A15_TransferClusters
A16_Lcn
A17_MoveDataStartingLcnQuadPart
A18_FlagsUseDelayedAllocation
A19_ValidClusters

Event ID 274 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_NtfsFullFileRefNumber_ScbFcbFileReference
A14_MoveDataStartingVcnQuadPart
A15_TransferClusters

Event ID 275 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_FcbNULLNtfsFullFileRefNumber_FcbFileReference0
A16_CcbNULLCcbFlags0

Event ID 276 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18_ScbAttributeNameBuffer
A19_ScbPersist
A20_CcbFlags

Event ID 277 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 278 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 279 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbPersist
A20_CcbNULLCcbFlags0

Event ID 280 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_ScbHeaderValidDataLengthQuadPart
A12_ScbHeaderFileSizeQuadPart
A13_QueryDaxExtentsFileOffset
A14_StartingVcn
A15_QueryDaxExtentsLength

Event ID 281 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_QueryDaxExtentsFileOffset
A11_QueryDaxExtentsLength
A12_EffectiveInputFileRegionLength
A13_StartingVcn
A14_BeyondEndVcn
A15_RemainingClusterCount
A16_LastVcnInFile

Event ID 282 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 283 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_RemainingClusterCount
A11_DataSetRangeIndex
A12_OutputBufferLength

Event ID 284 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExtentsDescriptorNumberOfValidRuns
A11_MaxRuns
A12_BytesReturned

Event ID 285 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_RemainingClusterCount
A11_ExtentsDescriptorNumberOfValidRuns

Event ID 286 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_RemainingClusterCount
A11_ExtentsDescriptorNumberOfValidRuns

Event ID 287 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExtentsDescriptorNumberOfValidRuns
A11_MaxRuns
A12_Status
A13_BytesReturned

Event ID 288 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExtentsDescriptorRunIndexBasePage
A11_ExtentsDescriptorRunIndexPageCount

Event ID 289 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ZeroStart
A11_ZeroEnd

Event ID 290 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ZeroStart
A11_ZeroEnd

Event ID 291 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_CcbFlags

Event ID 292 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ARGUMENT_PRESENTCcbCcbAccessFlags0
A20_ARGUMENT_PRESENTCreateContextCreateContextPreviouslyGrantedAccess0

Event ID 293 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_CcbFlags

Event ID 294 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_CcbNULLCcbFlags0

Event ID 295 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbVcbVpbRealDeviceFlags

Event ID 296 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_RenameCleanupTargetLinkFcb
A15_NtfsFullFileRefNumber_RenameCleanupTargetLinkFcbFileReference
A16_RenameCleanupTargetLinkFcbFcbState

Event ID 297 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_RenameCleanupTargetLinkFcb
A15_NtfsFullFileRefNumber_RenameCleanupTargetLinkFcbFileReference
A16_RenameCleanupTargetLinkFcbTxfFcbTxfNumWriters

Event ID 298 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_LcbToDeleteFcb
A15_NtfsFullFileRefNumber_LcbToDeleteFcbFileReference
A16_LcbToDelete
A17_WppCountedStringWLcbToDeleteFileNameAttrFileNameUSHORTLcbToDeleteFileNameAttrFileNameLength
A18_LcbToDeleteTxfNumWriters

Event ID 299 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_RenameCleanupTargetLinkFcb
A15_NtfsFullFileRefNumber_RenameCleanupTargetLinkFcbFileReference
A16_RenameCleanupTargetLinkFcbCleanupCount

Event ID 300 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_LcbToDeleteFcb
A15_NtfsFullFileRefNumber_LcbToDeleteFcbFileReference
A16_LcbToDelete
A17_WppCountedStringWLcbToDeleteFileNameAttrFileNameUSHORTLcbToDeleteFileNameAttrFileNameLength
A18_LcbToDeleteCleanupCount
A19_SplitPrimaryLcb
A20_SplitPrimaryLcbNULLWppCountedStringWSplitPrimaryLcbFileNameAttrFileNameUSHORTSplitPrimaryLcbFileNameAttrFileNameLengthWppCountedStringWNULL0
A21_SplitPrimaryLcbNULLSplitPrimaryLcbCleanupCount0

Event ID 301 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_LcbFcb
A15_NtfsFullFileRefNumber_LcbFcbFileReference
A16_LcbFcbFcbState
A17_Lcb
A18_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength
A19_LcbFileNameAttrFlags
A20_LcbLcbState

Event ID 302 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_ScbFcbInfoFileAttributes

Event ID 303 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TargetParentScbFcb
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference
A16_TargetParentScbFcbFcbState

Event ID 304 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TargetParentScbFcb
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference
A16_TargetParentScbFcbInfoFileAttributes
A17_TargetParentScbFcbFcbState

Event ID 305 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference

Event ID 306 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_NtfsFullFileRefNumber_TargetParentScbFcbFileReference

Event ID 307 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16__CcbFullFileName

Event ID 308 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16__CcbFullFileName
A17_TxfVisibleLinks

Event ID 309 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16__CcbFullFileName
A17_AccessStatus

Event ID 310 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TargetParentScbFcb
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference
A16__NewLinkName

Event ID 311 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TargetParentScbFcb
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference
A16__NewLinkName
A17_TargetParentScbFcbTxfRmcbRmState

Event ID 312 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_LcbFcb
A15_NtfsFullFileRefNumber_LcbFcbFileReference
A16_Lcb
A17_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength

Event ID 313 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_LcbFcb
A15_NtfsFullFileRefNumber_LcbFcbFileReference
A16_Lcb
A17_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength
A18_NtfsFullFileRefNumber_ParentScbFcbFileReference

Event ID 314 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_NextScbVcb
A12__NextScbVcbVolumeName
A13_WppCountedStringWNextScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHNextScbVcbVpb
A14_NextScbFcb
A15_NtfsFullFileRefNumber_NextScbFcbFileReference
A16_NextScbCleanupCount

Event ID 315 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_NextScbVcb
A12__NextScbVcbVolumeName
A13_WppCountedStringWNextScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHNextScbVcbVpb
A14_NextScbFcb
A15_NtfsFullFileRefNumber_NextScbFcbFileReference
A16_ByIdCcbs
A17_NextScbCleanupCount

Event ID 316 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbState
A20_ScbScbTypeDataHighWaterMark

Event ID 317 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_DirectoryScbVcb
A12__DirectoryScbVcbVolumeName
A13_WppCountedStringWDirectoryScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHDirectoryScbVcbVpb
A14_DirectoryScbFcb
A15_NtfsFullFileRefNumber_DirectoryScbFcbFileReference
A16_ULONGIrpIoStatusInformation
A17_BatchOplockCount

Event ID 318 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12_Fcb
A13_LocalFlagsEntireFlags

Event ID 319 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Scb

Event ID 320 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12_LocalFlagsEntireFlags

Event ID 321 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_VcbBitmapScb
A11_Vcb

Event ID 322 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_VcbMftScb
A11_Vcb

Event ID 323 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PNTFS_DISK_FLUSH_CONTEXTContextVcb
A11_Context

Event ID 324 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PNTFS_DISK_FLUSH_CONTEXTContextVcb
A11_Context
A12_NtfsDataDiskFlushContextCompletedWorkItemListFlink

Event ID 325 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 326 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 327 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Irp
A11_IrpContext
A12_IrpContextVcb
A13_IrpSpMinorFunction
A14_FsControlCode

Event ID 328 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState
A15_VcbDisallowDismountCount
A16_ExplicitLock10
A17_ReadULongNoFence_VcbCleanupCount
A18_UserHandleCountSystemHandleCountVcbExternalMetadataCleanupCount

Event ID 329 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 330 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Status

Event ID 331 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Status

Event ID 332 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbCloseCount
A15_VcbSystemFileCloseCount
A16_UserHandleCount

Event ID 333 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 334 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ActiveRmCount
A15_DefaultRmActive10

Event ID 335 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDVcbTxfVcbDefaultRm
A12_VcbTxfVcbDefaultRmNULL_VcbTxfVcbDefaultRmRmIdNULL

Event ID 336 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 337 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12__VolumeLabel
A13__VcbDeviceName

Event ID 338 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 339 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 340 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState
A15_VcbReadOnlyCloseCount
A16_VcbCloseCount
A17_VcbSystemFileCloseCount

Event ID 341 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 342 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 343 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 344 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbAccessFlags

Event ID 345 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbAccessFlags

Event ID 346 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbAccessFlags

Event ID 347 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0
A15_TypeOfOpen

Event ID 348 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0
A15_IrpRequestorMode

Event ID 349 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 350 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 351 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbAccessFlags
A15_CcbFlags

Event ID 352 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbAccessFlags
A15_CcbFlags
A16_CallerId
A17_ContextOwnerId

Event ID 353 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_FileObjectWriteAccess10

Event ID 354 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_ScbAttributeFlags

Event ID 355 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ZeroFlags
A12_IrpRequestorMode

Event ID 356 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Scb
A12_IrpSpFileObject

Event ID 357 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_EncryptionOperation

Event ID 358 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags

Event ID 359 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags

Event ID 360 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 361 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 362 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 363 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 364 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 365 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_HandleInfoHandleInfo
A19_IrpRequestorMode

Event ID 366 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_DasdCcbNULLDasdCcbAccessFlags0

Event ID 367 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbPersist
A20_HandleInfoHandleInfo

Event ID 368 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbFcbState2
A17_Scb
A18_ScbAttributeTypeCode
A19__ScbAttributeName
A20_ScbPersist
A21_HandleInfoHandleInfo

Event ID 369 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbFcbState
A17_Scb
A18_ScbAttributeTypeCode
A19__ScbAttributeName
A20_ScbPersist
A21_HandleInfoHandleInfo
A22_IrpRequestorMode

Event ID 370 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_ScbFcbFcbState
A17_HandleInfoHandleInfo

Event ID 371 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_HandleInfoHandleInfo

Event ID 372 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbShareAccessWriters

Event ID 373 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 374 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TypeOfOpen
A15_IrpSpFileObjectWriteAccess10
A16_ScbFcb
A17_NtfsFullFileRefNumber_ScbFcbFileReference
A18_ScbAttributeTypeCode
A19_ScbFcbFcbState
A20_CcbNULL_CcbFullFileNameNULL

Event ID 375 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 376 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PVOIDVcb
A11_InputParameter

Event ID 377 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 378 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 379 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_IrpContextVcb
A12__IrpContextVcbVolumeName
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb
A14_NtfsDataFlags

Event ID 380 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 381 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbVcbState

Event ID 382 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 383 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_CcbNULLCcbAccessFlags0

Event ID 384 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_IrpContextVcb
A12__IrpContextVcbVolumeName
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb

Event ID 385 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScrubResumeContextSystemScbIndex
A11_ScrubResumeContextResumeVcn
A12_ScrubResumeContextResumeVcnOffset

Event ID 386 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_ScrubResumeContextResumeVcn
A12_ScrubResumeContextResumeVcnOffset

Event ID 387 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ScrubResumeContextSystemScbIndex

Event ID 388 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TypeOfOpen
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17__CcbFullFileName
A18_CcbAccessFlags

Event ID 389 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_ScbTxfScb

Event ID 390 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 391 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_ScrubContextOperationStatus
A12_ScrubContextNumberOfBytesRepaired
A13_ScrubContextNumberOfBytesFailed
A14_ScrubContextErrorFileOffset
A15_ScrubContextErrorLength
A16_ScrubContextParityExtentDataNumberOfParityExtents

Event ID 392 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_Status
A12_ScrubContextNumberOfBytesRepaired
A13_ScrubContextNumberOfBytesFailed
A14_ScrubContextParityExtentDataNumberOfParityExtents

Event ID 393 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_InternalFileReference

Event ID 394 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_InternalFileReference

Event ID 395 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_ScrubIoCount
A12_IrpCancel
A13_ScrubContextParityExtentDataNumberOfParityExtents

Event ID 396 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11__ScbAttributeName

Event ID 397 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11__ScbAttributeName

Event ID 398 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn

Event ID 399 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_FileScrubOffset
A12_SectorAlignedVdl

Event ID 400 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn

Event ID 401 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn
A12_ClusterCount

Event ID 402 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn

Event ID 403 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_DsmRangeStartingOffset
A12_DsmRangeStartingOffsetDsmRangeLengthInBytes
A13_DsmRangeLengthInBytes
A14_StartingVcn
A15_StartingVcnOffset
A16_SectorAlignedVdl

Event ID 404 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn
A12_ScrubContextErrorFileOffset
A13_ScrubbedLength
A14_ScrubContextOperationStatus
A15_ScrubContextNumberOfBytesFailed
A16_ScrubContextNumberOfBytesRepaired
A17_NewParityExtentCount

Event ID 405 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_Status

Event ID 406 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_Status

Event ID 407 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_ScbTxfScb

Event ID 408 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11__ScbAttributeName

Event ID 409 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11__ScbAttributeName

Event ID 410 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 411 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 412 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn

Event ID 413 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn

Event ID 414 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartingVcn
A12_ClusterCount

Event ID 415 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_RepairDataSetRangeStartingOffset
A12_RepairDataSetRangeStartingOffsetRepairDataSetRangeLengthInBytes
A13_RepairDataSetRangeLengthInBytes
A14_RepairFileOffset

Event ID 416 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_Status

Event ID 417 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_IrpStatus

Event ID 418 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_RepairCopiesOutputStatus

Event ID 419 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TypeOfOpen
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17__CcbFullFileName
A18_CcbAccessFlags

Event ID 420 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TypeOfOpen
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 421 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TypeOfOpen
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 422 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TypeOfOpen
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 423 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName

Event ID 424 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_TypeOfOpen
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_IrpRequestorMode

Event ID 425 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_VcbVcbState

Event ID 426 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbPersist
A20_CcbNULLCcbFlags0

Event ID 427 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbInfoFileAttributes
A17_IrpSpFlags

Event ID 428 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_IrpRequestorMode

Event ID 429 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_VcbVcbState

Event ID 430 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbPersist
A20_CcbNULLCcbFlags0

Event ID 431 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbInfoFileAttributes
A17_IrpSpFlags

Event ID 432 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_NtfsFullFileRefNumber_FcbFileReference
A15_CcbNULL_CcbFullFileNameNULL
A16_CcbNULLCcbAccessFlags0

Event ID 433 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_ScbAttributeTypeCode
A18_ScbFcbFcbState2
A19_CcbNULL_CcbFullFileNameNULL
A20_CcbNULLCcbAccessFlags0
A21_CcbNULLCcbFlags20

Event ID 434 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_ScbAttributeTypeCode
A18_CcbNULL_CcbFullFileNameNULL
A19_CcbNULLCcbAccessFlags0

Event ID 435 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0

Event ID 436 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PsGetCurrentThread
A12_Status
A13__DeletedFiles

Event ID 437 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PsGetCurrentThread
A12_Status

Event ID 438 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PsGetCurrentThread
A12_Status
A13__FileNameToDelete

Event ID 439 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PsGetCurrentThread
A12_Status

Event ID 440 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PsGetCurrentThread
A12_Status

Event ID 441 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0
A19_EffectiveMode

Event ID 442 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_StartOffset
A12_Length
A13_StartVcn
A14_BeyondEndVcn

Event ID 443 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status
A11_OutputNumBadRanges

Event ID 444 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FsInputRangeIndex
A11_FsInputRangesFsInputRangeIndexFileOffset
A12_FsInputRangesFsInputRangeIndexVolumeOffset
A13_FsInputRangesFsInputRangeIndexLengthInBytes

Event ID 445 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_Status
A12_BOOLEANAbnormalTermination

Event ID 446 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_Status

Event ID 447 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_IrpContextVcb
A12__IrpContextVcbVolumeName
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb

Event ID 448 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 449 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Table
A11_ParentScb
A12__ParentScbScbTypeIndexNormalizedName
A13_RemainingName

Event ID 450 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 451 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FoundLcb
A11__FoundLcbExactCaseLinkLinkName

Event ID 452 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 453 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Table
A11_NewHashEntryHashValue
A12_NewHashEntryFullNameLength
A13_NewHashEntryHashLcb
A14__NewHashEntryHashLcbExactCaseLinkLinkName

Event ID 454 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Table
A11_HashValue
A12_HashLcb
A13__HashLcbExactCaseLinkLinkName

Event ID 455 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbCheckpointInjectionCount

Event ID 456 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_PercentFull
A12_VcbWaitForCcLoggedDataActivityCount

Event ID 457 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 458 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 459 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 460 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbCleanCheckpointCount

Event ID 461 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbOverflowedDPTCount

Event ID 462 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbFuzzyCheckpointCount

Event ID 463 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbFlushOldestFOCount

Event ID 464 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_NtfsFullSegmentNumber_ScbFcbFileReference

Event ID 465 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_DirtyPageContextOldestFileObject

Event ID 466 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 467 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 468 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 469 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextTransactionId

Event ID 470 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextTransactionId

Event ID 471 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextOriginatingIrp
A12_PsGetCurrentThread
A13_IrpContextExceptionStatus

Event ID 472 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextOriginatingIrp
A12_PsGetCurrentThread
A13_IrpContextExceptionStatus

Event ID 473 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextOriginatingIrp
A12_PsGetCurrentThread
A13_IrpContextExceptionStatus
A14_FailedFlushCount

Event ID 474 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextOriginatingIrp
A12_PsGetCurrentThread
A13_IrpContextExceptionStatus

Event ID 475 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextOriginatingIrp
A12_PsGetCurrentThread
A13_IrpContextExceptionStatus

Event ID 476 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextTransactionId

Event ID 477 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextTransactionId

Event ID 478 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_ActiveLsnQuadPart
A12_ClearAll

Event ID 479 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 480 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 481 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_ClustersClusterCount

Event ID 482 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 483 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 484 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_Clusters
A12_ClustersClusterCount
A13_ClustersLsnQuadPart
A14_ClustersFlags

Event ID 485 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_Clusters
A12_i
A13_StartingLcn
A14_ClusterCount

Event ID 486 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 487 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 488 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 489 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 490 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Status

Event ID 491 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 492 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_StartingLcn
A12_ULONGClusterCount

Event ID 493 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_StartingLcnStartingIndex
A12_runLength

Event ID 494 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_Status

Event ID 495 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_MarkUnusedContext

Event ID 496 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 497 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_McbScb
A11_Mcb
A12_StartingVcn
A13_Count

Event ID 498 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Mcb

Event ID 499 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_McbScb
A11_Mcb
A12_Vcn
A13_Lcn
A14_RunCount

Event ID 500 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Mcb
A11_Result

Event ID 501 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_McbScb
A11_Mcb
A12_StartingVcn
A13_EndingVcn
A14_TruncateOnly

Event ID 502 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Mcb

Event ID 503 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_BootSector

Event ID 504 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_BootSector
A12_CheckNumber

Event ID 505 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_IrpContextExceptionStatus

Event ID 506 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12__VolumeLabel
A13__VcbDeviceName

Event ID 507 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 508 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 509 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext

Event ID 510 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_AttrListAllocationSize

Event ID 511 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_Scb
A13_AttrListAllocationSize

Event ID 512 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExceptionCode

Event ID 513 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExceptionCode

Event ID 514 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExceptionCode

Event ID 515 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContextLogFullReason
A11_BackTrace0
A12_BackTrace1
A13_BackTrace2
A14_BackTrace3
A15_BackTrace4
A16_BackTrace5
A17_BackTrace6
A18_BackTrace7
A19_BackTrace8
A20_BackTrace9
A21_BackTrace10
A22_BackTrace11
A23_BackTrace12
A24_BackTrace13
A25_BackTrace14
A26_BackTrace15
A27_BackTrace16
A28_BackTrace17
A29_BackTrace18
A30_BackTrace19

Event ID 516 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExceptionCode

Event ID 517 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_ExceptionCode

Event ID 518 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_ExceptionCode

Event ID 519 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Irp
A12_IrpContextVcb
A13_NtfsFailedAborts
A14_GetExceptionCode

Event ID 520 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Irp
A12_IrpContextVcb
A13_NextScb
A14_PULONGLONG_NextScbFcbFileReference

Event ID 521 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpSpParametersWriteByteOffsetHighPart
A11_IrpSpParametersWriteByteOffsetLowPart

Event ID 522 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ExceptionCode
A11_IrpSpParametersWriteByteOffsetHighPart
A12_IrpSpParametersWriteByteOffsetLowPart

Event ID 523 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpSpMajorFunction
A11_IrpSpMinorFunction
A12_Irp
A13_IrpContext
A14_Status

Event ID 524 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpSpMajorFunction
A11_IrpSpMinorFunction
A12_Irp
A13_IrpContext
A14_Status

Event ID 525 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 526 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 527 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_MinTrimTotalSize

Event ID 528 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_MaxTrimTotalSize

Event ID 529 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_IrpSpMinorFunction

Event ID 530 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_IrpSpMinorFunction

Event ID 531 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_IrpSpMinorFunction

Event ID 532 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDVcbTxfVcbDefaultRm
A12__VcbTxfVcbDefaultRmRmId

Event ID 533 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_IrpContextVcb
A12__IrpContextVcbVolumeName
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb

Event ID 534 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_ScbFcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17__CcbFullFileName
A18_CcbAccessFlags
A19_CcbFlags

Event ID 535 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb

Event ID 536 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_IrpSpFileObjectWriteAccess

Event ID 537 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_IrpSpFileObjectWriteAccess

Event ID 538 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags
A18_IrpSpFileObjectWriteAccess

Event ID 539 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbLogFileObject
A12_IrpContext

Event ID 540 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext

Event ID 541 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_VcbLogFileObject
A12_IrpContext

Event ID 542 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextTransactionId

Event ID 543 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextTransactionId

Event ID 544 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_FileRecordSegmentNumberHighPart
A12_FileRecordSegmentNumberLowPart
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment

Event ID 545 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_FileRecordSegmentNumberHighPart
A12_FileRecordSegmentNumberLowPart
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment

Event ID 546 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_FileRecordSegmentNumberHighPart
A12_FileRecordSegmentNumberLowPart
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment
A14_AttributeTypeCode
A15_LogRecordRecordOffset
A16_Length

Event ID 547 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_FileRecordSegmentNumberHighPart
A12_FileRecordSegmentNumberLowPart
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment
A14_PATTRIBUTE_RECORD_HEADERDataTypeCode

Event ID 548 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_FileRecordSegmentNumberHighPart
A12_FileRecordSegmentNumberLowPart
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment
A14_NtfsFullSegmentNumber_FileReference

Event ID 549 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_FileRecordSegmentNumberHighPart
A12_FileRecordSegmentNumberLowPart
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment
A14_AttributeFormNonresidentAllocatedLength
A15_AttributeFormNonresidentFileSize
A16_AttributeFormNonresidentValidDataLength
A17_AttributeFormNonresidentTotalAllocated
A18_SizesAllocationSize
A19_SizesFileSize
A20_SizesValidDataLength
A21_SizesTotalAllocated

Event ID 550 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12__Bitmap

Event ID 551 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12__Bitmap

Event ID 552 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference

Event ID 553 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName
A17_CcbAccessFlags

Event ID 554 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16__CcbFullFileName

Event ID 555 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbTxfFcbTxfNumWriters

Event ID 556 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_Status

Event ID 557 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbInfoFileAttributes

Event ID 558 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbInfoFileAttributes

Event ID 559 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference

Event ID 560 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_ThisFcbInfoFileAttributes
A17_IrpSpFlags

Event ID 561 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_CcbAccessFlags
A17_AccessStatus

Event ID 562 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ThisFcbVcb
A12__ThisFcbVcbVolumeName
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb
A14_ThisFcb
A15_NtfsFullFileRefNumber_ThisFcbFileReference
A16_NextScb
A17_NextScbAttributeTypeCode
A18__NextScbAttributeName

Event ID 563 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0

Event ID 564 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbVcbState

Event ID 565 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0

Event ID 566 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0

Event ID 567 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 568 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 569 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 570 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 571 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbFcbState
A17_CcbNULL_CcbFullFileNameNULL

Event ID 572 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0

Event ID 573 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0
A18_Flags

Event ID 574 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0

Event ID 575 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_Status

Event ID 576 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_Status

Event ID 577 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb
A11_ScbTotalAllocated

Event ID 578 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_CurrentClusters
A11_CurrentClustersLsnQuadPart

Event ID 579 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ClustersLinkAsHead
A11_FlagsToMatch
A12_InsertAfter

Event ID 580 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Clusters
A11_ClustersFlags

Event ID 581 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Clusters
A11_NumberOfRuns

Event ID 582 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Clusters

Event ID 583 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Event ID 584 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FlagOnClustersFlagsDEALLOCATED_CLUSTERS_FLAG_NO_DANGLING_MDL
A11_Clusters
A12_Lcn
A13_ClusterCount

Event ID 585 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FlagOnClustersFlagsDEALLOCATED_CLUSTERS_FLAG_NO_DANGLING_MDL
A11_Clusters
A12_Lcn
A13_ClusterCount

Event ID 586 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_TxfFcbFlags
A17_ShareMode

Event ID 587 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_GrantedAccess

Event ID 588 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_GrantedAccess

Event ID 589 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_GrantedAccess
A17_NextTxfVscbReaderCleanupCount

Event ID 590 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_CallerFunction
A12_CallerFile
A13_CallerLineNumber
A14_PVOIDTxfRmcb
A15__TxfRmcbRmId
A16_PVOIDTxfTrans
A17__TxfTransKtmUow
A18_AbortReasonStatus

Event ID 591 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_CallerFunction
A12_CallerFile
A13_CallerLineNumber
A14_PVOIDTxfRmcb
A15__TxfRmcbRmId
A16_PVOIDTxfTrans
A17__TxfTransKtmUow
A18_Status

Event ID 592 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_TxfTrans
A14__TxfTransKtmUow

Event ID 593 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_TxfTrans
A14__TxfTransKtmUow

Event ID 594 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDCalloutParametersTxfFlushTxfRmcb
A12__CalloutParametersTxfFlushTxfRmcbRmId
A13_GetExceptionCode

Event ID 595 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__

Event ID 596 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__

Event ID 597 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__

Event ID 598 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__

Event ID 599 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__

Event ID 600 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__

Event ID 601 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__

Event ID 602 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_FailureStatus

Event ID 603 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_FailureStatus

Event ID 604 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_Status

Event ID 605 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbTxfVcbFlags

Event ID 606 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_TempStatus
A12_PVOIDVcb

Event ID 607 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_GetExceptionCode
A12_Status
A13_PVOIDVcb

Event ID 608 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDVcb
A12_TXF_MAX_RESET_ATTEMPTS_ON_MOUNT
A13_OldStatus

Event ID 609 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_GetExceptionCode
A12_PVOIDVcb

Event ID 610 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_NT_SUCCESSStatusSucceededFAILED
A12_PVOIDTxfRmcb
A13__TxfRmcbRmId
A14_Status

Event ID 611 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 612 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 613 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 614 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbTxfVcbFlags

Event ID 615 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 616 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_VcbTxfVcbFlags

Event ID 617 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 618 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_LogNestingLevel
A14_DiskNestingLevel

Event ID 619 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 620 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 621 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13__ClfsRestartAreaRmId

Event ID 622 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_Status
A12_PVOIDTxfRmcb
A13__TxfRmcbRmId

Event ID 623 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 624 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 625 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 626 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_Status
A14_AbnormalTerminationabnormaltermination

Event ID 627 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_TxfIsDefaultRmTxfRmcbdefaultsecondary
A12_PVOIDTxfRmcb
A13__TxfRmcbRmId
A14_ForceDirtyShutdownDIRTYCLEAN

Event ID 628 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 629 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_FcbFileReference
A16_FcbCleanupCount

Event ID 630 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_FILEID_FROM_SOURCEFileNLine
A11_LINENUM_FROM_SOURCEFileNLine
A12_TxfRmcb
A13__TxfRmcbRmId
A14_Status

Event ID 631 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__OldGuid
A13__TxfRmcbRmId

Event ID 632 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_PVOIDTxfTrans
A14__TxfTransKtmUow
A15_Status

Event ID 633 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__OldGuid
A13__TxfRmcbRmId

Event ID 634 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_RmRootFcbVcb
A12__RmRootFcbVcbVolumeName
A13_WppCountedStringWRmRootFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHRmRootFcbVcbVpb
A14_RmRootFcb

Event ID 635 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_FcbVcb
A12__FcbVcbVolumeName
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb
A14_BackupInfoFlags

Event ID 636 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 637 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_Status
A12_PVOIDFileObject

Event ID 638 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 639 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__CcbFullFileName
A19_CcbFlags

Event ID 640 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_CcbTxfFo
A18_CcbTxfFoKtmTrans
A19_ScbFcbTxfRmcb
A20_CcbFullFileNameBuffer

Event ID 641 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17__CcbFullFileName
A18_CcbAccessFlags
A19_FileObjectWriteAccess
A20_FileObjectDeleteAccess

Event ID 642 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_ExceptionCode

Event ID 643 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_TransactionNotification
A12_TransactionAlreadyPreparedPREPARED
A13__TxfTransKtmUow
A14_PVOIDTxfRmcb
A15__TxfRmcbRmId
A16_Status

Event ID 644 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_TxfTrans
A14__TxfTransKtmUow

Event ID 645 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_TxfTrans
A14__TxfTransKtmUow

Event ID 646 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTransTxfRmcb
A12__TransTxfRmcbRmId
A13_FlushStatus

Event ID 647 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_Trans
A14__TransKtmUow

Event ID 648 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_CallStack0
A12_CallStack1
A13_CallStack2
A14_CallStack3
A15_CallStack4

Event ID 649 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_Trans
A14__TransKtmUow

Event ID 650 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_Status
A12_PVOIDTrans
A13__TransKtmUow
A14_PVOIDTxfRmcb
A15__TxfRmcbRmId

Event ID 651 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_Status
A12_PVOIDTxfRmcb
A13__TxfRmcbRmId
A14_PVOIDTrans
A15__TransKtmUow

Event ID 652 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 653 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 654 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 655 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 656 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_OldestTrans
A14__OldestTransKtmUow

Event ID 657 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_Status
A14_OldestTrans
A15__OldestTransKtmUow

Event ID 658 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 659 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 660 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_PVOIDTransToDereference
A14__TransToDereferenceKtmUow
A15_Status

Event ID 661 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 662 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 663 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PinnedStatus
A12_PVOIDTxfRmcb
A13__TxfRmcbRmId
A14_Status

Event ID 664 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 665 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 666 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 667 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 668 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 669 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 670 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 671 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 672 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 673 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 674 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId
A13_IsEncrypted_TopsFcbInfoencryptedcompressed

Event ID 675 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 676 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 677 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 678 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 679 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 680 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 681 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 682 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 683 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10___FUNCTION__
A11_PVOIDTxfRmcb
A12__TxfRmcbRmId

Event ID 684 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 685 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_VcbFirstValidUsn
A13_FirstValidUsn
A14_TrackUsnJournalFileSize
A15_TrackUsnJournalAllocationSize
A16_TrackUsnJournalMaxSize
A17_TrackUsnJournalDeltaAllocation

Event ID 686 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_FirstValidUsn1
A13_SavedReserved
A14_RequiredReserved

Event ID 687 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_UsnJournalHeaderAllocationSizeQuadPart
A13_UsnJournalHeaderFileSizeQuadPart
A14_UsnJournalHeaderValidDataLengthQuadPart
A15_UsnJournalTotalAllocated

Event ID 688 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_UsnJournalHeaderAllocationSizeQuadPart
A13_UsnJournalHeaderFileSizeQuadPart
A14_UsnJournalHeaderValidDataLengthQuadPart
A15_UsnJournalTotalAllocated

Event ID 689 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext

Event ID 690 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext

Event ID 691 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference

Event ID 692 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_Fcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_CcbNULL_CcbFullFileNameNULL
A17_CcbNULLCcbAccessFlags0

Event ID 693 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_CcbNULL_CcbFullFileNameNULL
A18_CcbNULLCcbAccessFlags0

Event ID 694 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_ScbVcb
A12__ScbVcbVolumeName
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb
A14_ScbFcb
A15_NtfsFullFileRefNumber_ScbFcbFileReference
A16_Scb
A17_ScbAttributeTypeCode
A18__ScbAttributeName
A19_ScbCleanupCount

Event ID 695 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_IrpContextOriginatingIrp
A13_PsGetCurrentThread
A14_ScbHeaderAllocationSizeQuadPart
A15_ScbHeaderFileSizeQuadPart
A16_ScbHeaderValidDataLengthQuadPart
A17_NewAllocationSize

Event ID 696 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_IrpContextOriginatingIrp
A13_PsGetCurrentThread
A14_ScbHeaderAllocationSizeQuadPart
A15_ScbHeaderFileSizeQuadPart
A16_ScbHeaderValidDataLengthQuadPart
A17_ScbTotalAllocated

Event ID 697 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_IrpContextOriginatingIrp
A13_PsGetCurrentThread

Event ID 698 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_IrpContext
A12_IrpContextOriginatingIrp
A13_PsGetCurrentThread

Event ID 699 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_IrpContextOriginatingIrp
A12_PsGetCurrentThread
A13_IrpContextExceptionStatus

Event ID 700 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_RemainingClusterCount
A11_Scb
A12_Vcn
A13_Lcn
A14_ClusterCount

Event ID 701 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 702 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 703 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 704 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 705 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 706 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 707 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb

Event ID 708 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Vcb
A12__VolumeLabel
A13__VcbDeviceName

Event ID 709 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpContext
A11_Status
A12_FileReference
A13_Fcb
A14_Source
A15_TopLevelExceptionStatus

Event ID 710 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Vcb
A11_WasDirty
A12_NtfsFullSegmentNumber_BugCheckFileReference
A13_Source

Event ID 711 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_FsInformationClass
A18_Scb

Event ID 712 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_TypeOfOpen
A12_Vcb
A13__VcbVolumeName
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A15_Fcb
A16_NtfsFullFileRefNumber_ScbFcbFileReference
A17_FsInformationClass
A18_Scb

Event ID 713 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_IrpSpParametersWriteByteOffsetHighPart
A11_IrpSpParametersWriteByteOffsetLowPart
A12_IrpContextTopLevelIrpContextExceptionStatus

Event ID 714 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_Scb

Event ID 715 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_PsGetCurrentThread
A11_Vcb
A12__VcbVolumeName
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb
A14_ByteRange
A15_HIGHEST_WRITABLE_SECTOR_ON_ACTIVE_VOLUMEVcbSectorSizeInfoLogicalBytesPerSector

Event ID 716 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_StartingVbo
A11_ScbHeaderValidDataLengthQuadPart
A12_ptrdiff_tScb

Event ID 717 —

Provider
Microsoft-Windows-NtfsLog_cdac24ce683a371108c05bb363714355
Channel
Operational

Fields

NameDescription
A10_ByteRange
A11_SectorAlignedVdl
A12_ptrdiff_tScb