Microsoft-Pef-WFP-MessageProvider

19 events across 1 channel

Event ID 2000: The generic ETW message fragment that ORT can reassemble.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

The generic ETW message fragment that ORT can reassemble.

Message #

The generic ETW message fragment that ORT can reassemble.

Fields #

NameDescription
FragmentEventId UInt16
GroupId UInt32
ByteLength UInt32
Payload Binary

Event ID 10001: Driver Load

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

Driver Load.

Message #

Driver Load

Fields #

NameDescription
DriverName UnicodeString
MajorVersion UInt16
MinorVersion UInt16

Event ID 10002: Driver Unload

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

Driver Unload.

Message #

Driver Unload

Fields #

NameDescription
DriverName UnicodeString
MajorVersion UInt16
MinorVersion UInt16

Event ID 10003: Callout Register

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

Callout Register.

Message #

Callout Register

Fields #

NameDescription
Callout UInt32

Event ID 10004: Callout Unregister

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

Callout Unregister.

Message #

Callout Unregister

Fields #

NameDescription
Callout UInt32

Event ID 10005: Callout Notify Filter Add

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

Callout Notify Filter Add.

Message #

Callout Notify Filter Add

Fields #

NameDescription
FilterId UInt64
Callout UInt32
FilterWeight UInt64

Event ID 10006: Callout Notify Filter Delete

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

Callout Notify Filter Delete.

Message #

Callout Notify Filter Delete

Fields #

NameDescription
FilterId UInt64
Callout UInt32
FilterWeight UInt64

Event ID 20001: An error was encountered while loading the driver.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

An error was encountered while loading the driver.

Message #

An error was encountered while loading the driver.

Fields #

NameDescription
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20002: An error was encountered while unloading the driver.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

An error was encountered while unloading the driver.

Message #

An error was encountered while unloading the driver.

Fields #

NameDescription
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20003: An error was encountered while registering a callout.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

An error was encountered while registering a callout.

Message #

An error was encountered while registering a callout.

Fields #

NameDescription
Callout UInt32
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20004: An error was encountered while unregistering a callout.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

An error was encountered while unregistering a callout.

Message #

An error was encountered while unregistering a callout.

Fields #

NameDescription
Callout UInt32
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20005: An error was encountered in a classify function.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

An error was encountered in a classify function.

Message #

An error was encountered in a classify function.

Fields #

NameDescription
Callout UInt32
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 60011: The Transport Layer Message for IPv4.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress UInt32
DestinationAddress UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ByteLength UInt16
MessageFrame Binary

Event ID 60012: The Transport Layer Message for IPv4.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress UInt32
DestinationAddress UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ByteLength UInt16
MessageFrame Binary

Event ID 60021: The Transport Layer Message for IPv6.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress Binary
DestinationAddress Binary
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ByteLength UInt16
MessageFrame Binary

Event ID 60022: The Transport Layer Message for IPv6.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress Binary
DestinationAddress Binary
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ByteLength UInt16
MessageFrame Binary

Event ID 60031: The ALE Layer Message for IPv4.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

The ALE Layer Message for IPv4.

Message #

The ALE Layer Message for IPv4.

Fields #

NameDescription
SourceAddress UInt32
DestinationAddress UInt32
SourcePort UInt16
DestinationPort UInt16
Luid UInt64
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ProcessId UInt64
ByteLength UInt16
ProcessPath Binary

Event ID 60041: The Transport Layer Message for IPv6.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

The Transport Layer Message for IPv6.

Message #

The Transport Layer Message for IPv6.

Fields #

NameDescription
SourceAddress Binary
DestinationAddress Binary
SourcePort UInt16
DestinationPort UInt16
Luid UInt64
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ProcessId UInt64
ByteLength UInt16
ProcessPath Binary

Event ID 60050: A packet has been discarded.

#
Provider
Microsoft-Pef-WFP-MessageProvider
Channel
Diagnostic

Description

A packet has been discarded.

Message #

A packet has been discarded.

Fields #

NameDescription
DiscardModule UInt8
DiscardReason UInt32
DiscardFilterID UInt64

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID c22d1b14-c242-49de-9f17-1d76b8b9c458

Defined in WFPCapture.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02

Downloads