Microsoft-Windows-Ras-NdisWanPacketCapture

3 events across 1 channel

Event ID 5001: Sending NDIS Wan Packet (FragmentSize bytes).

#
Provider
Microsoft-Windows-Ras-NdisWanPacketCapture
Channel
Diagnostic
Opcode
Info

Description

Sending NDIS Wan Packet (FragmentSize bytes).

Message #

Sending NDIS Wan Packet (%3 bytes)

Fields #

NameDescription
RoutingDomainID UnicodeString
RRASUserName UnicodeString
FragmentSize UInt32
Fragment Binary

Event ID 5002: Reciving NDIS Wan Packet (FragmentSize bytes).

#
Provider
Microsoft-Windows-Ras-NdisWanPacketCapture
Channel
Diagnostic
Opcode
Info

Description

Reciving NDIS Wan Packet (FragmentSize bytes).

Message #

Reciving NDIS Wan Packet (%3 bytes)

Fields #

NameDescription
RoutingDomainID UnicodeString
RRASUserName UnicodeString
FragmentSize UInt32
Fragment Binary

Event ID 5003: Event.

#
Provider
Microsoft-Windows-Ras-NdisWanPacketCapture
Channel
Diagnostic
Opcode
Info

Description

Event: param1

Message #

Event: %1

Fields #

NameDescription
param1 UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID d84521f7-2235-4237-a7c0-14e3a9676286

Defined in ndiswan.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.2849 · captured 2026-06-02
  • Win11-26200.6584 · schema read from the registered manifest · binary version 10.0.26100.5074 · captured 2026-06-02

Downloads

Credits

  • Microsoft - authored the ETW manifests and PDBs the schema comes from
  • jdu2600 - the event-schema TSV format this catalog adopted
  • nasbench - the tool that dumps registered providers and manifests