Microsoft-Windows-VolumeSnapshot-Driver

92 events across 2 channels

Event IDTitleChannel
0Analytic
1Analytic
2Analytic
3Analytic
4Analytic
5Analytic
6Analytic
7Analytic
8Analytic
9Analytic
10Analytic
11Analytic
12Analytic
13Analytic
14Analytic
15Analytic
16Analytic
17Analytic
18Analytic
19Analytic
20Analytic
21Analytic
22Analytic
23Analytic
24Analytic
25Analytic
26Analytic
27Analytic
28Analytic
29Analytic
30Analytic
31Analytic
32Analytic
33Analytic
100The volume snapshot driver has begun processing for volume online.Operational
101The volume snapshot driver has completed processing for volume online.Operational
102The volume snapshot driver encountered an error while performing processing for …Operational
103Activation of discovered snapshots began.Operational
104Activation of discovered snapshots completed.Operational
105Activation of discovered snapshots encountered an error.Operational
106A persistent snapshot was activated.Operational
107Reading of a snapshot diff area's metadata began.Operational
108Reading of a snapshot diff area's metadata completed.Operational
109Reading of a snapshot diff area's metadata encountered an error.Operational
110Validation of diff area files began.Operational
111Validation of diff area files completed.Operational
112Validation of diff area files encountered an error.Operational
113The volume is preparing to be taken offline.Operational
114The volume snapshot driver has begun processing for dismount.Operational
115The volume snapshot driver has completed processing for dismount.Operational
116The volume snapshot driver has begun processing for volume offline.Operational
117The volume snapshot driver has completed processing for volume offline.Operational
118The volume snapshot driver encountered an error while performing processing for …Operational
119The volume snapshot driver encountered an error while performing processing for …Operational
120Activation of discovered snapshots took too long and was aborted.Operational
121The volume snapshot driver was unable to log an event to the legacy System event …Operational
122The volume snapshot driver encountered an error when attempting to determine …Operational
123Persistent snapshots are not supported on this edition of Windows.Operational
1000PrepareForSnapshot (Enter)Analytic
1001PrepareForSnapshot (Leave)Analytic
1002PreExposure (Enter)Analytic
1003PreExposure (Leave)Analytic
1004AdjustBitmap (Enter)Analytic
1005AdjustBitmap (Leave)Analytic
1006EndCommit (Enter)Analytic
1007EndCommit (Leave)Analytic
1008Activate (Enter)Analytic
1009Activate (Leave)Analytic
1010SetIgnorable (Enter)Analytic
1011SetIgnorable (Leave)Analytic
1012ComputeIgnorableProduct (Enter)Analytic
1013ComputeIgnorableProduct (Leave)Analytic
1014Dismount (Enter)Analytic
1015Dismount (Leave)Analytic
1016Remount (Enter)Analytic
1017Remount (Leave)Analytic
1018DeleteProcess (Enter)Analytic
1019DeleteProcess (Leave)Analytic
1020Revert (Enter)Analytic
1021Revert (Leave)Analytic
1022ComputeProtectedBitmap (Enter)Analytic
1023ComputeProtectedBitmap (Leave)Analytic
1024FlushHoldFs (Enter)Analytic
1025FlushHoldFs (Leave)Analytic
1026ActivateLoop (Enter)Analytic
1027ActivateLoop (Leave)Analytic
1028ValidateDiffAreaFiles (Enter)Analytic
1029ValidateDiffAreaFiles (Leave)Analytic
1030VolumesSafeForWrite (Enter)Analytic
1031VolumesSafeForWrite (Leave)Analytic
1032DiscoverSnapshots (Enter)Analytic
1033DiscoverSnapshots (Leave)Analytic

Event ID 0 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 1 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
SnapshotGuid

Event ID 2 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 3 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 4 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
SnapshotGuid

Event ID 5 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
SnapshotGuid

Event ID 6 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 7 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 8 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 9 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 10 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
SnapshotGuid

Event ID 11 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
SnapshotGuid

Event ID 12 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
SnapshotGuid

Event ID 13 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
SnapshotGuid

Event ID 14 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 15 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 16 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 17 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 18 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 19 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 20 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 21 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 22 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 23 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 24 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 25 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 26 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 27 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 28 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 29 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 30 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 31 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID

Event ID 32 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 33 —

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Fields

NameDescription
RealThreadID
VolumeGuid

Event ID 100 — The volume snapshot driver has begun processing for volume online.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational
Level
4
Samples
1

Message

The volume snapshot driver has begun processing for volume online.

Volume GUID: %1

Guidance:
When a volume is brought online the volume snapshot driver scans for any persistent snapshots that may be on the volume.

You should expect this event when a volume is brought online.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Example Event

system:
  provider: Microsoft-Windows-VolumeSnapshot-Driver
  guid: 67FE2216-727A-40CB-94B2-C02211EDB34A
  event_source_name: ''
  event_id: 100
  version: 0
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:13.425270+00:00'
  event_record_id: 87
  correlation: {}
  execution:
    process_id: 4
    thread_id: 228
  channel: Microsoft-Windows-VolumeSnapshot-Driver/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  TargetVolumeGuid: 7597D2A3-4404-4F99-B979-6233378A81BF
  SourceFile: '0x1'
  SourceLine: 39024
  SourceTag: 124
message: ''

References

Event ID 101 — The volume snapshot driver has completed processing for volume online.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational
Level
4
Samples
1

Message

The volume snapshot driver has completed processing for volume online.

Volume GUID: %1

Guidance:
The volume snapshot driver was able to scan for any persistent snapshots on this volume.

You should expect this event when a volume is brought online.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Example Event

system:
  provider: Microsoft-Windows-VolumeSnapshot-Driver
  guid: 67FE2216-727A-40CB-94B2-C02211EDB34A
  event_source_name: ''
  event_id: 101
  version: 0
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2023-11-06T06:25:13.433430+00:00'
  event_record_id: 88
  correlation: {}
  execution:
    process_id: 4
    thread_id: 228
  channel: Microsoft-Windows-VolumeSnapshot-Driver/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  TargetVolumeGuid: 7597D2A3-4404-4F99-B979-6233378A81BF
  SourceFile: '0x1'
  SourceLine: 39187
  SourceTag: 125
message: ''

References

Event ID 102 — The volume snapshot driver encountered an error while performing processing for volume online.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume snapshot driver encountered an error while performing processing for volume online.

Error: %2

Volume GUID: %1

Guidance:
When a volume is brought online the volume snapshot driver scans for any persistent snapshots that may be on the volume.  In case of an error this scan is not performed.  The error may have originated in storage drivers beneath the volume snapshot driver; check their logs.

If the error is STATUS_DEVICE_NOT_CONNECTED this means the volume is in snapshot protection mode and has been taken offline to prevent loss of snapshots.

Fields

NameDescription
TargetVolumeGuid
Error
SourceFile
SourceLine
SourceTag

Event ID 103 — Activation of discovered snapshots began.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Activation of discovered snapshots began.

Volume GUID: %1

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver scans for and activates any persistent snapshots that may be on the volume.

You should expect this event when a volume is brought online or reverted to a snapshot.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Event ID 104 — Activation of discovered snapshots completed.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Activation of discovered snapshots completed.

Volume GUID: %1
Total Number of Snapshots Found: %2
Number of Snapshots Marked for Delete: %3
Number of Visible Snapshots Found: %4

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver scans for and activates any persistent snapshots that may be on the volume.  Some snapshots may be marked 'visible', meaning they were exposed as a local volume or file share.  Some detected snapshots may be marked 'deleted', meaning they are no longer available for use and their diff area space will be reclaimed when all older snapshots are deleted.  Look for instances of event 106 to see each snapshot that was discovered and whether it was 'visible' or 'deleted'.

You should expect this event when a volume is brought online or reverted to a snapshot.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SnapshotCount
CountDeleted
CountVisible
SourceFile
SourceLine
SourceTag

Event ID 105 — Activation of discovered snapshots encountered an error.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Activation of discovered snapshots encountered an error.

Error: %2

Volume GUID: %1

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver scans for and activates any persistent snapshots that may be on the volume.  Unless the volume is in snapshot protection mode or the error code indicates the volume is offline, a failure during this process results in loss of all snapshots on the volume.

Fields

NameDescription
TargetVolumeGuid
Error
SourceFile
SourceLine
SourceTag

Event ID 106 — A persistent snapshot was activated.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

A persistent snapshot was activated.

Volume GUID: %1
Snapshot GUID: %2
Snapshot Marked Deleted: %3
Snapshot Visible: %4
Snapshot Commit Timestamp: %5

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver scans for and activates any persistent snapshots that may be on the volume.  If the snapshot is 'visible', it was exposed as a local volume or file share.  If the snapshot is 'deleted', it is no longer available for use and its diff area space will be reclaimed when all older snapshots are deleted.

You should expect this event when a volume containing persistent snapshots is brought online or reverted to a snapshot.  If all discovered snapshots are successfully activated you should expect event 104, otherwise you will see event 105.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SnapshotGuid
Deleted
Visible
CommitTime
SourceFile
SourceLine
SourceTag

Event ID 107 — Reading of a snapshot diff area's metadata began.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Reading of a snapshot diff area's metadata began.

Volume GUID: %1
Snapshot GUID: %2

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver reads the diff area for the most-recent persistent snapshot (if any).  The diff area for earlier persistent snapshots is typically read the first time the snapshot is read from.

You should expect this event when a volume is brought online, reverted to a snapshot, or when reading from a persistent snapshot for the first time after bringing a volume online.  This event may also occur if a volume is dismounted that contains snapshots that have not been read since the volume was brought online.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 108 — Reading of a snapshot diff area's metadata completed.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Reading of a snapshot diff area's metadata completed.

Volume GUID: %1
Snapshot GUID: %2
Count of 1MB Reads: %3
Count of 16KB Reads: %4
Diff Area Metadata Size: %5 Bytes
Total Data Read: %6 Bytes

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver reads the diff area for the most-recent persistent snapshot (if any).  The diff area for earlier persistent snapshots is typically read the first time the snapshot is read from.  The size of the diff area metadata may be less than the total number of bytes read if the diff area is discontiguous on disk.

You should expect this event when a volume is brought online, reverted to a snapshot, or when reading from a persistent snapshot for the first time after bringing a volume online.  This event may also occur if a volume is dismounted that contains snapshots that have not been read since the volume was brought online.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SnapshotGuid
LargeReadCount
SmallReadCount
TableDataBytes
TotalBytesRead
SourceFile
SourceLine
SourceTag

Event ID 109 — Reading of a snapshot diff area's metadata encountered an error.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Reading of a snapshot diff area's metadata encountered an error.

Error: %3

Volume GUID: %1
Snapshot GUID: %2
Count of 1MB Reads: %4
Count of 16KB Reads: %5
Amount of Diff Area Metadata Read: %6 Bytes
Total Data Read: %7 Bytes

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver reads the diff area for the most-recent persistent snapshot (if any).  The diff area for earlier persistent snapshots is typically read the first time the snapshot is read from.  Unless the volume is in snapshot protection mode, a failure during this process results in loss of all snapshots on the volume.

Fields

NameDescription
TargetVolumeGuid
SnapshotGuid
Error
LargeReadCount
SmallReadCount
TableDataBytes
TotalBytesRead
SourceFile
SourceLine
SourceTag

Event ID 110 — Validation of diff area files began.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Validation of diff area files began.

Volume GUID: %1

Guidance:
When a volume is mounted, the volume snapshot driver reads and validates all the diff area files located on the volume.  These diff area files may be for persistent snapshots of the volume being mounted, or for persistent snapshots of other volumes.

You should expect this event when mounting a volume.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Event ID 111 — Validation of diff area files completed.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Validation of diff area files completed.

Number of Diff Areas: %2

Guidance:
When a volume is mounted, the volume snapshot driver reads and validates all the diff area files located on the volume.  These diff area files may be for persistent snapshots of the volume being mounted, or for persistent snapshots of other volumes.

You should expect this event when mounting a volume.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
DiffAreaCount
SourceFile
SourceLine
SourceTag

Event ID 112 — Validation of diff area files encountered an error.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Validation of diff area files encountered an error.

Error: %2

Volume GUID: %1

Guidance:
When a volume is mounted, the volume snapshot driver reads and validates all the diff area files located on the volume.  These diff area files may be for persistent snapshots of the volume being mounted, or for persistent snapshots of other volumes.  A failure during this process results in loss of all snapshots whose diff area files are located on the volume, unless those snapshots are of volumes that are in snapshot protection mode.

Fields

NameDescription
TargetVolumeGuid
Error
SourceFile
SourceLine
SourceTag

Event ID 113 — The volume is preparing to be taken offline.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume is preparing to be taken offline.

Volume GUID: %1

Guidance:
Some system services, such as the cluster service, inform the volume snapshot driver when they are about to take the volume offline.

You should expect this event when an entity such as the cluster service prepares to take a volume offline.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Event ID 114 — The volume snapshot driver has begun processing for dismount.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational
Level
4
Samples
1

Message

The volume snapshot driver has begun processing for dismount.

Volume GUID: %1

Guidance:
When a volume is dismounted, the volume snapshot driver closes any handles it may have open on the dismounting volume, such as handles to diff areas.  All auto-release snapshots that have diff areas on the dismounting volume are deleted at this time. The volume snapshot driver may also perform some work to detect whether any future direct writes to the volume are to diff area space for persistent snapshots.  If such writes occur this detection work allows the volume snapshot driver to destroy the snapshots, since the direct volume writes may corrupt them.

You should expect this event when a volume dismounts.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Example Event

system:
  provider: Microsoft-Windows-VolumeSnapshot-Driver
  guid: 67FE2216-727A-40CB-94B2-C02211EDB34A
  event_source_name: ''
  event_id: 114
  version: 0
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2022-04-07T16:45:03.737710+00:00'
  event_record_id: 9
  correlation: {}
  execution:
    process_id: 4
    thread_id: 32
  channel: Microsoft-Windows-VolumeSnapshot-Driver/Operational
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-18
event_data:
  TargetVolumeGuid: E856EAFF-60EA-4D9C-8467-32D0B50DBFFC
  SourceFile: '0x1'
  SourceLine: 37521
  SourceTag: 119
message: ''

References

Event ID 115 — The volume snapshot driver has completed processing for dismount.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational
Level
4
Samples
1

Message

The volume snapshot driver has completed processing for dismount.

Volume GUID: %1

Guidance:
When a volume is dismounted, the volume snapshot driver closes any handles it may have open on the dismounting volume, such as handles to diff areas.  All auto-release snapshots that have diff areas on the dismounting volume are deleted at this time. The volume snapshot driver may also perform some work to detect whether any future direct writes to the volume are to diff area space for persistent snapshots.  If such writes occur this detection work allows the volume snapshot driver to destroy the snapshots, since the direct volume writes may corrupt them.

You should expect this event when a volume dismounts.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Example Event

system:
  provider: Microsoft-Windows-VolumeSnapshot-Driver
  guid: 67FE2216-727A-40CB-94B2-C02211EDB34A
  event_source_name: ''
  event_id: 115
  version: 0
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2022-04-07T16:45:03.737712+00:00'
  event_record_id: 10
  correlation: {}
  execution:
    process_id: 4
    thread_id: 32
  channel: Microsoft-Windows-VolumeSnapshot-Driver/Operational
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-18
event_data:
  TargetVolumeGuid: E856EAFF-60EA-4D9C-8467-32D0B50DBFFC
  SourceFile: '0x1'
  SourceLine: 38322
  SourceTag: 122
message: ''

References

Event ID 116 — The volume snapshot driver has begun processing for volume offline.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume snapshot driver has begun processing for volume offline.

Volume GUID: %1

Guidance:
When a volume is taken offline, the volume snapshot driver disables any persistent snapshots that still exist for the volume (autorelease snapshots were deleted when the volume was dismounted).  Snapshots of other volumes whose diff areas are on the offlining volume are destroyed, unless those volumes are in snapshot protection mode.  In that case those volumes are taken offline.

You should expect this event when a volume is taken offline.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Event ID 117 — The volume snapshot driver has completed processing for volume offline.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume snapshot driver has completed processing for volume offline.

Volume GUID: %1

Guidance:
When a volume is taken offline, the volume snapshot driver disables any persistent snapshots that still exist for the volume (autorelease snapshots were deleted when the volume was dismounted).  Snapshots of other volumes whose diff areas are on the offlining volume are destroyed, unless those volumes are in snapshot protection mode.  In that case those volumes are taken offline.

You should expect this event when a volume is taken offline.  No user action is required.

Fields

NameDescription
TargetVolumeGuid
SourceFile
SourceLine
SourceTag

Event ID 118 — The volume snapshot driver encountered an error while performing processing for volume offline.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume snapshot driver encountered an error while performing processing for volume offline.

Error: %2

Volume GUID: %1

Guidance:
When a volume is taken offline, the volume snapshot driver disables any persistent snapshots that still exist for the volume (autorelease snapshots were deleted when the volume was dismounted).  Snapshots of other volumes whose diff areas are on the offlining volume are destroyed, unless those volumes are in snapshot protection mode.  In that case those volumes are taken offline.

If the error is STATUS_INSUFFICIENT_RESOURCES (0xc000009a), the volume snapshot driver may have been unable to allocate memory.  Other error codes originate from lower drivers.  Please check their log(s) for further information.

Fields

NameDescription
TargetVolumeGuid
Error
SourceFile
SourceLine
SourceTag

Event ID 119 — The volume snapshot driver encountered an error while performing processing for dismount.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume snapshot driver encountered an error while performing processing for dismount.

Error: %3
Error Details: %2

Volume GUID: %1

Guidance:
When a volume is dismounted, the volume snapshot driver closes any handles it may have open on the dismounting volume, such as handles to diff areas.  All auto-release snapshots that have diff areas on the dismounting volume are deleted at this time. The volume snapshot driver may also perform some work to detect whether any future direct writes to the volume are to diff area space for persistent snapshots.  If such writes occur this detection work allows the volume snapshot driver to destroy the snapshots, since the direct volume writes may corrupt them.

A failure during this process results in loss of all snapshots whose diff area files are located on the volume, unless those snapshots are of volumes that are in snapshot protection mode.

Fields

NameDescription
TargetVolumeGuid
PersistentDeleteReason
PersistentDeleteStatus
SourceFile
SourceLine
SourceTag

Event ID 120 — Activation of discovered snapshots took too long and was aborted.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Activation of discovered snapshots took too long and was aborted.

Volume GUID: %1
Timeout Value (in seconds): %2

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver scans for and activates any persistent snapshots that may be on the volume.  This process took longer than the amount of time allowed on this system, so activation has been aborted.  Unless the volume is in snapshot protection mode, all snapshots on this volume have been deleted.

Fields

NameDescription
TargetVolumeGuid
TimeoutInSeconds
SourceFile
SourceLine
SourceTag

Event ID 121 — The volume snapshot driver was unable to log an event to the legacy System event log.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume snapshot driver was unable to log an event to the legacy System event log.

Volume Name: %2
Diff Volume Name (if applicable): %4
Original Error Event Code: %5
Original Error Status: %6
Cause of Logging Failure:%10

Fields

NameDescription
VolumeNameLength
VolumeName
DiffVolumeNameLength
DiffVolumeName
OriginalErrorLogCode
OriginalErrorStatus
OriginalSourceFile
OriginalSourceLine
OriginalSourceTag
ErrorStatus
SourceFile
SourceLine
SourceTag

Event ID 122 — The volume snapshot driver encountered an error when attempting to determine whether the volume is clustered.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

The volume snapshot driver encountered an error when attempting to determine whether the volume is clustered.

Error: %2

Volume GUID: %1

Guidance:
When a volume is brought online or reverted to a snapshot, the volume snapshot driver scans for and activates any persistent snapshots that may be on the volume.  This process attempts to determine whether the volume is part of a cluster shared resource, but the query to determine this failed.

This error does not indicate that any snapshots have been deleted.  You should expect this event if the volume is on a dynamic disk or is managed by a third-party volume manager.

Fields

NameDescription
TargetVolumeGuid
Error
SourceFile
SourceLine
SourceTag

Event ID 123 — Persistent snapshots are not supported on this edition of Windows.

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Operational

Message

Persistent snapshots are not supported on this edition of Windows.

Guidance:
This edition of Windows does not support creation of persistent snapshots.  Autorelease snapshots are supported.

Fields

NameDescription
SourceFile
SourceLine
SourceTag

Event ID 1000 — PrepareForSnapshot (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

PrepareForSnapshot (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1001 — PrepareForSnapshot (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

PrepareForSnapshot (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1002 — PreExposure (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

PreExposure (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1003 — PreExposure (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

PreExposure (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1004 — AdjustBitmap (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

AdjustBitmap (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1005 — AdjustBitmap (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

AdjustBitmap (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1006 — EndCommit (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

EndCommit (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1007 — EndCommit (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

EndCommit (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1008 — Activate (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Activate (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1009 — Activate (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Activate (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1010 — SetIgnorable (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

SetIgnorable (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1011 — SetIgnorable (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

SetIgnorable (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1012 — ComputeIgnorableProduct (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ComputeIgnorableProduct (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1013 — ComputeIgnorableProduct (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ComputeIgnorableProduct (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1014 — Dismount (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Dismount (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1015 — Dismount (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Dismount (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1016 — Remount (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Remount (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1017 — Remount (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Remount (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1018 — DeleteProcess (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

DeleteProcess (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1019 — DeleteProcess (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

DeleteProcess (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1020 — Revert (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Revert (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1021 — Revert (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

Revert (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1022 — ComputeProtectedBitmap (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ComputeProtectedBitmap (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1023 — ComputeProtectedBitmap (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ComputeProtectedBitmap (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1024 — FlushHoldFs (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

FlushHoldFs (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1025 — FlushHoldFs (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

FlushHoldFs (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1026 — ActivateLoop (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ActivateLoop (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1027 — ActivateLoop (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ActivateLoop (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1028 — ValidateDiffAreaFiles (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ValidateDiffAreaFiles (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1029 — ValidateDiffAreaFiles (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

ValidateDiffAreaFiles (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1030 — VolumesSafeForWrite (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

VolumesSafeForWrite (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1031 — VolumesSafeForWrite (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

VolumesSafeForWrite (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag

Event ID 1032 — DiscoverSnapshots (Enter)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

DiscoverSnapshots (Enter)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
SourceFile
SourceLine
SourceTag

Event ID 1033 — DiscoverSnapshots (Leave)

Provider
Microsoft-Windows-VolumeSnapshot-Driver
Channel
Analytic

Message

DiscoverSnapshots (Leave)

Fields

NameDescription
DiagPrefixLength
DiagPrefix
VolumeNameLength
VolumeName
TargetVolumeGuid
SnapshotGuid
ExitStatus
SourceFile
SourceLine
SourceTag