Microsoft-Windows-VolumeSnapshot-Driver
92 events across 2 channels
Event ID 0 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 1 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
SnapshotGuid GUID | — |
Event ID 2 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 3 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 4 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
SnapshotGuid GUID | — |
Event ID 5 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
SnapshotGuid GUID | — |
Event ID 6 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 7 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 8 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 9 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 10 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
SnapshotGuid GUID | — |
Event ID 11 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
SnapshotGuid GUID | — |
Event ID 12 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
SnapshotGuid GUID | — |
Event ID 13 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
SnapshotGuid GUID | — |
Event ID 14 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 15 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 16 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 17 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 18 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 19 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 20 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 21 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 22 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 23 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 24 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 25 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 26 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 27 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 28 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 29 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 30 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 31 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
Event ID 32 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 33 —
Fields #
| Name | Description |
|---|---|
RealThreadID UInt32 | — |
VolumeGuid GUID | — |
Event ID 100 — The volume snapshot driver has begun processing for volume online.
#Description
The volume snapshot driver has begun processing for volume online.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 100,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:25:13.425270+00:00",
"event_record_id": 87,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 228
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "7597D2A3-4404-4F99-B979-6233378A81BF",
"SourceFile": "0x1",
"SourceLine": 39024,
"SourceTag": 124
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 101 — The volume snapshot driver has completed processing for volume online.
#Description
The volume snapshot driver has completed processing for volume online.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 101,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:25:13.433430+00:00",
"event_record_id": 88,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 228
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "7597D2A3-4404-4F99-B979-6233378A81BF",
"SourceFile": "0x1",
"SourceLine": 39187,
"SourceTag": 125
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 102 — The volume snapshot driver encountered an error while performing processing for volume online.
Event ID 103 — Activation of discovered snapshots began.
Description
Activation of discovered snapshots began.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 103,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.486348+00:00",
"event_record_id": 184,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SourceFile": "0x1",
"SourceLine": 22127,
"SourceTag": 93
},
"message": ""
}
Event ID 104 — Activation of discovered snapshots completed.
Description
Activation of discovered snapshots completed.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SnapshotCount UInt32 | — |
CountDeleted UInt32 | — |
CountVisible UInt32 | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 104,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.508914+00:00",
"event_record_id": 190,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotCount": 3,
"CountDeleted": 0,
"CountVisible": 0,
"SourceFile": "0x1",
"SourceLine": 23009,
"SourceTag": 107
},
"message": ""
}
Event ID 105 — Activation of discovered snapshots encountered an error.
Event ID 106 — A persistent snapshot was activated.
Description
A persistent snapshot was activated.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SnapshotGuid GUID | — |
Deleted Boolean | — |
Visible Boolean | — |
CommitTime SYSTEMTIME | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 106,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:27:09.499366+00:00",
"event_record_id": 189,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 352
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465863F8-1B56-11F1-9FBF-C6B26F270F0B",
"Deleted": false,
"Visible": false,
"CommitTime": "2026-03-11T03:42:04.594000Z",
"SourceFile": "0x1",
"SourceLine": 20745,
"SourceTag": 92
},
"message": ""
}
Event ID 107 — Reading of a snapshot diff area's metadata began.
Description
Reading of a snapshot diff area's metadata began.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SnapshotGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 107,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:28:15.280120+00:00",
"event_record_id": 192,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4156
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465845A3-1B56-11F1-9FBF-C6B26F270F0B",
"SourceFile": "0x7",
"SourceLine": 4286,
"SourceTag": 84
},
"message": ""
}
Event ID 108 — Reading of a snapshot diff area's metadata completed.
Description
Reading of a snapshot diff area's metadata completed.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SnapshotGuid GUID | — |
LargeReadCount UInt32 | — |
SmallReadCount UInt32 | — |
TableDataBytes UInt64 | — |
TotalBytesRead UInt64 | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 108,
"version": 2,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:28:15.323019+00:00",
"event_record_id": 193,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4156
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "CE657EBB-70C7-4B8B-A13F-FF11B9725249",
"SnapshotGuid": "465845A3-1B56-11F1-9FBF-C6B26F270F0B",
"LargeReadCount": 3,
"SmallReadCount": 2,
"TableDataBytes": 3162112,
"TotalBytesRead": 3178496,
"SourceFile": "0x7",
"SourceLine": 4683,
"SourceTag": 89
},
"message": ""
}
Event ID 109 — Reading of a snapshot diff area's metadata encountered an error.
Description
Reading of a snapshot diff area's metadata encountered an error.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SnapshotGuid GUID | — |
Error HexInt32 | — |
LargeReadCount UInt32 | — |
SmallReadCount UInt32 | — |
TableDataBytes UInt64 | — |
TotalBytesRead UInt64 | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Event ID 110 — Validation of diff area files began.
Event ID 111 — Validation of diff area files completed.
Event ID 112 — Validation of diff area files encountered an error.
Event ID 113 — The volume is preparing to be taken offline.
Event ID 114 — The volume snapshot driver has begun processing for dismount.
#Description
The volume snapshot driver has begun processing for dismount.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 114,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:45:03.737710+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 32
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E856EAFF-60EA-4D9C-8467-32D0B50DBFFC",
"SourceFile": "0x1",
"SourceLine": 37521,
"SourceTag": 119
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 115 — The volume snapshot driver has completed processing for dismount.
#Description
The volume snapshot driver has completed processing for dismount.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 115,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2022-04-07T16:45:03.737712+00:00",
"event_record_id": 10,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 32
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E856EAFF-60EA-4D9C-8467-32D0B50DBFFC",
"SourceFile": "0x1",
"SourceLine": 38322,
"SourceTag": 122
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 116 — The volume snapshot driver has begun processing for volume offline.
Description
The volume snapshot driver has begun processing for volume offline.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 116,
"version": 0,
"level": 4,
"task": 0,
"opcode": 1,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:08:10.764027+00:00",
"event_record_id": 113,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4464
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E3E83FDF-1F17-11F1-9FBA-010101010000",
"SourceFile": "0x1",
"SourceLine": 34284,
"SourceTag": 113
},
"message": ""
}
Event ID 117 — The volume snapshot driver has completed processing for volume offline.
Description
The volume snapshot driver has completed processing for volume offline.
Message #
Fields #
| Name | Description |
|---|---|
TargetVolumeGuid GUID | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-VolumeSnapshot-Driver",
"guid": "67FE2216-727A-40CB-94B2-C02211EDB34A",
"event_source_name": "",
"event_id": 117,
"version": 0,
"level": 4,
"task": 0,
"opcode": 2,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:08:10.764058+00:00",
"event_record_id": 114,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 4464
},
"channel": "Microsoft-Windows-VolumeSnapshot-Driver/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"TargetVolumeGuid": "E3E83FDF-1F17-11F1-9FBA-010101010000",
"SourceFile": "0x1",
"SourceLine": 34312,
"SourceTag": 114
},
"message": ""
}
Event ID 118 — The volume snapshot driver encountered an error while performing processing for volume offline.
Event ID 119 — The volume snapshot driver encountered an error while performing processing for dismount.
Event ID 120 — Activation of discovered snapshots took too long and was aborted.
Event ID 121 — The volume snapshot driver was unable to log an event to the legacy System event log.
Description
The volume snapshot driver was unable to log an event to the legacy System event log.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | — |
VolumeName UnicodeString | — |
DiffVolumeNameLength UInt16 | — |
DiffVolumeName UnicodeString | — |
OriginalErrorLogCode UInt32 | — |
OriginalErrorStatus HexInt32 | — |
OriginalSourceFile HexInt32 | — |
OriginalSourceLine UInt16 | — |
OriginalSourceTag UInt32 | — |
ErrorStatus HexInt32 | — |
SourceFile HexInt32 | — |
SourceLine UInt16 | — |
SourceTag UInt32 | — |