Microsoft-Windows-StorDiag
58 events across 4 channels
Event ID 1 — ClassPnP IO request complete
Message
Fields
| Name | Description |
|---|---|
RequestProcessTime | — |
OriginalIrp | — |
Irp | — |
MajorFunction | — |
RequestType | — |
SrbStatus | — |
DeviceNumber | — |
Event ID 2 — ClassPnP Enqueue Idle IO request
Message
Fields
| Name | Description |
|---|---|
Irp | — |
CurrentIOCount | — |
ActiveIOCount | — |
DeviceNumber | — |
Event ID 3 — ClassPnP Boost Idle IO request
Message
Fields
| Name | Description |
|---|---|
Irp | — |
Thread | — |
CurrentIOCount | — |
ActiveIOCount | — |
DeviceNumber | — |
Event ID 4 — CopyOffload request servicing time taken by lower driver stack(s).
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
RequestDurationin100ns | — |
Irp | — |
Command | — |
ServiceAction | — |
SrbStatus | — |
OriginalIrp | — |
Event ID 5 — Dispatching a CopyOffload read request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
IsWrite | — |
FirstStartingLBA | — |
LengthOfTransferinbytes | — |
Event ID 6 — Dispatching a CopyOffload write request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
IsWrite | — |
FirstStartingLBA | — |
LengthOfTransferinbytes | — |
Event ID 7 — Completing a CopyOffload IO (read/write) request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
TransferredLength | — |
Flags | — |
NTStatus | — |
Event ID 8 — Device returned sense data.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
SenseKey | — |
AddSense | — |
AddSenseQ | — |
CurrentRetryCount | — |
Event ID 201 — Request servicing time taken by lower driver stack(s).
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
RequestDurationin100ns | — |
Irp | — |
Command | — |
SrbStatus | — |
OriginalIrp | — |
Event ID 202 — Dispatching a read request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Command | — |
LengthOfTransferinbytes | — |
LBA | — |
OriginalIrp | — |
NvCachePriority | — |
Event ID 203 — Dispatching a write request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Command | — |
LengthOfTransferinbytes | — |
LBA | — |
OriginalIrp | — |
NvCachePriority | — |
Event ID 204 — Dispatching a read request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Command | — |
LengthOfTransferinbytes | — |
LBA | — |
OriginalIrp | — |
NvCachePriority | — |
Event ID 205 — Dispatching a write request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Command | — |
LengthOfTransferinbytes | — |
LBA | — |
OriginalIrp | — |
NvCachePriority | — |
Event ID 206 — Dispatching a read request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Command | — |
LengthOfTransferinbytes | — |
LBA | — |
OriginalIrp | — |
NvCachePriority | — |
Event ID 207 — Dispatching a write request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Command | — |
LengthOfTransferinbytes | — |
LBA | — |
OriginalIrp | — |
NvCachePriority | — |
Event ID 208 — Completing an IO (read/write) request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
NTStatus | — |
SrbStatus | — |
ScsiStatus | — |
SenseKey | — |
AddSense | — |
AddSenseQ | — |
OriginalIrp | — |
NumberOfTimesRetried | — |
Event ID 209 — Retrying an IO (read/write) request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
CurrentRetryCount | — |
NTStatus | — |
SrbStatus | — |
ScsiStatus | — |
SenseKey | — |
AddSense | — |
AddSenseQ | — |
Event ID 210 — Flush request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Bus | — |
Target | — |
LUN | — |
Event ID 211 — Flush request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
NTStatus | — |
SrbStatus | — |
ScsiStatus | — |
SenseKey | — |
AddSense | — |
AddSenseQ | — |
OriginalIrp | — |
Event ID 212 — Dispatching an IOCTL.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
MajorFunction | — |
MinorFunction | — |
Parameter | — |
Event ID 213 — Dispatching a WMI request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
MajorFunction | — |
MinorFunction | — |
Parameter | — |
Event ID 214 — Completing a non-read/write request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Status | — |
Event ID 215 — Dispatching a power request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
MinorFunction | — |
Type | — |
OldState | — |
NewState | — |
Action | — |
PowerStateContext | — |
Event ID 216 — Completing a power request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Status | — |
Event ID 217 — Dispatching a PnP request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
MinorFunction | — |
Type | — |
DeviceObject | — |
Event ID 218 — Completing a PnP request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
Status | — |
Event ID 219 — Completing a PnP enumeration request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
NumberOfChildren | — |
Status | — |
Event ID 220 — Performing a queue-related operation.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
QueueTag | — |
Operation | — |
Status | — |
Event ID 221 — Dispatching a PassThrough request.
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
Irp | — |
MajorFunction | — |
MinorFunction | — |
Parameter | — |
Event ID 222 — Upperlevel Trim request servicing time.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
RequestDurationin100ns | — |
UpperLevelIrp | — |
IrpStatus | — |
DsmFlags | — |
DataSetRangesCount | — |
DataSetRanges | — |
Event ID 223 — Downlevel Unmap SRB request servicing time taken by lower driver stack(s)
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
RequestDurationin100ns | — |
OriginalIrp | — |
SrbStatus | — |
SrbFlags | — |
MaxAllowedLbaCount | — |
MaxAllowedBlockDescriptorCount | — |
LbaSizeinBytes | — |
Srb_BlockDescriptorCount | — |
Srb_BlockDescriptors | — |
Event ID 224 — Report Zone Latency
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
RequestDurationin100ns | — |
UpperLevelIrp | — |
IrpStatus | — |
IsPartial | — |
StartingOffset | — |
BufferSize | — |
Event ID 225 — Reset Write Pointer Latency
Message
Fields
| Name | Description |
|---|---|
DeviceNumber | — |
RequestDurationin100ns | — |
UpperLevelIrp | — |
IrpStatus | — |
ResetAll | — |
StartingOffset | — |
Event ID 226 — Completing a failed IOCTL request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
IoctlControlCode | — |
Event ID 500 — Completing a failed upper level read request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
LBA | — |
TransferByteCount | — |
NvCachePriority | — |
PagingPriority | — |
Event ID 501 — Completing a failed upper level write request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
LBA | — |
TransferByteCount | — |
NvCachePriority | — |
PagingPriority | — |
Event ID 502 — Completing a failed upper level paging read request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
LBA | — |
TransferByteCount | — |
NvCachePriority | — |
PagingPriority | — |
Event ID 503 — Completing a failed upper level paging write request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
LBA | — |
TransferByteCount | — |
NvCachePriority | — |
PagingPriority | — |
Event ID 504 — Completing a failed IOCTL request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
IoctlControlCode | — |
Event ID 505 — Completing a failed Read SCSI SRB request
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
DownLevelIrpStatus | — |
SrbStatus | — |
ScsiStatus | — |
SenseKey | — |
AdditionalSenseCode | — |
AdditionalSenseCodeQualifier | — |
CdbByteCount | — |
CdbBytes | — |
NumberOfRetriesDone | — |
Event ID 506 — Completing a failed Write SCSI SRB request
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
DownLevelIrpStatus | — |
SrbStatus | — |
ScsiStatus | — |
SenseKey | — |
AdditionalSenseCode | — |
AdditionalSenseCodeQualifier | — |
CdbByteCount | — |
CdbBytes | — |
NumberOfRetriesDone | — |
Event ID 507 — Completing a failed non-ReadWrite SCSI SRB request
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
DownLevelIrpStatus | — |
SrbStatus | — |
ScsiStatus | — |
SenseKey | — |
AdditionalSenseCode | — |
AdditionalSenseCodeQualifier | — |
CdbByteCount | — |
CdbBytes | — |
NumberOfRetriesDone | — |
Example Event
system:
provider: Microsoft-Windows-StorDiag
guid: F5D05B38-80A6-4653-825D-C414E4AB3C68
event_source_name: ''
event_id: 507
version: 1
level: 2
task: 200
opcode: 101
keywords: 576460752437641216
time_created: '2022-04-07T17:41:19.261973+00:00'
event_record_id: 10
correlation:
ActivityID: 00000000-0000-0000-0000-000000000001
execution:
process_id: 4
thread_id: 32
channel: Microsoft-Windows-Storage-ClassPnP/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
DeviceGUID: E9A1B7AB-024C-F6F4-5089-48CC840C29D0
DeviceNumber: 1
Vendor: VendorCo
Model: ProductCode
FirmwareVersion: '2.00'
SerialNumber: '9207032533193411390'
DownLevelIrpStatus: '0xc000000d'
SrbStatus: 132
ScsiStatus: 2
SenseKey: 5
AdditionalSenseCode: 32
AdditionalSenseCodeQualifier: 0
CdbByteCount: 16
CdbBytes: 9E100000000000000000000000200000
NumberOfRetriesDone: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 508 — Completing a failed Non-SCSI SRB request
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
DownLevelIrpStatus | — |
SrbStatus | — |
SrbFunction | — |
SrbFlags | — |
NumberOfRetriesDone | — |
Event ID 509 — Completing a failed PNP request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
IrpMinorFunction | — |
PnPType | — |
PnPUsageInPath | — |
CurrentPnpState | — |
PreviousPnpState | — |
PagingPathUsageCount | — |
HibernationPathUsageCount | — |
DumpPathUsageCount | — |
Event ID 510 — Completing a failed Power request.
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
IrpMinorFunction | — |
PowerSystemContext | — |
PowerStateType | — |
PowerState | — |
PowerShutdownType | — |
CurrentPowerState | — |
ContextPowerChangeState | — |
Event ID 511 — Completing a failed WMI request
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
IrpStatus | — |
IrpMinorFunction | — |
WmiDataBlockGUID | — |
WmiProviderId | — |
Event ID 512 — Get Storage Firmware Information
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
Status | — |
InputBufferLength | — |
OutputBufferLength | — |
DeviceNumber | — |
PortDriverCodeSet | — |
FirmwareGetInfoSupport | — |
QueryFlag | — |
Event ID 513 — Download Storage Firmware
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
Status | — |
InputBufferLength | — |
DeviceNumber | — |
PortDriverCodeSet | — |
FirmwareGetInfoSupport | — |
HWFirmwareSupportUpgrade | — |
ImagePayloadAlignment | — |
SlotCount | — |
SlotIndex | — |
FWImageVersion | — |
FWSize | — |
FWSlot | — |
FWImageBufferSize | — |
Flags | — |
FWImageOffset | — |
Event ID 514 — Activate New Storage Firmware
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
Status | — |
InputBufferLength | — |
DeviceNumber | — |
PortDriverCodeSet | — |
FirmwareGetInfoSupport | — |
HWFirmwareSupportUpgrade | — |
SlotCount | — |
SlotIndex | — |
FWImageVersion | — |
FWSize | — |
FWSlot | — |
Flags | — |
Event ID 515 — Query Device Telemetry
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
T10VendorIdLength | — |
T10VendorId | — |
DataSet1Length | — |
DataSet2Length | — |
DataSet3Length | — |
DataSet4Length | — |
DataVersion | — |
ReasonIdentifierLength | — |
ReasonIdentifier | — |
Event ID 516 — Failed to process zone command asynchronously
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
DsmAction | — |
Event ID 517 — Read capacity failed with SMR device
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
DefaultValueUsed | — |
BytesPerSector | — |
SectorShift | — |
NTStatus | — |
Event ID 518 — Zone count mismatch
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
ActualZoneCount | — |
DeviceZoneCount | — |
ZoneGroupCount | — |
BytesPerSector | — |
Event ID 519 — Retrieve zone information failed
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
NTStatus | — |
BytesPerSector | — |
Event ID 520 — Query Command Duration Limit support and its Mode Page
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
NTStatus | — |
CommandOpCode | — |
T2CDLPage | — |
CDLPage | — |
Event ID 521 — Query Command Duration Limit Mode Page failed
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
NTStatus | — |
CDLSupported | — |
PageSavable | — |
T2CDLPage | — |
CDLPage | — |
Event ID 522 — Set Command Duration Limit Mode Page failed
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
NTStatus | — |
CDLSupported | — |
PageSavable | — |
T2CDLPage | — |
CDLPage | — |
Event ID 523 — Read capacity failed
Message
Fields
| Name | Description |
|---|---|
DeviceGUID | — |
DeviceNumber | — |
Vendor | — |
Model | — |
FirmwareVersion | — |
SerialNumber | — |
DefaultValueUsed | — |
BytesPerSector | — |
SectorShift | — |
NTStatus | — |