Microsoft-Pef-WFP-MessageProvider

Event ID 2000: The generic ETW message fragment that ORT can reassemble.

#
Channel
Diagnostic

Fields #

NameDescription
FragmentEventId UInt16
GroupId UInt32
ByteLength UInt32
Payload Binary

Event ID 10001: Driver Load

#
Channel
Diagnostic

Fields #

NameDescription
DriverName UnicodeString
MajorVersion UInt16
MinorVersion UInt16

Event ID 10002: Driver Unload

#
Channel
Diagnostic

Fields #

NameDescription
DriverName UnicodeString
MajorVersion UInt16
MinorVersion UInt16

Event ID 10003: Callout Register

#
Channel
Diagnostic

Fields #

NameDescription
Callout UInt32

Event ID 10004: Callout Unregister

#
Channel
Diagnostic

Fields #

NameDescription
Callout UInt32

Event ID 10005: Callout Notify Filter Add

#
Channel
Diagnostic

Fields #

NameDescription
FilterId UInt64
Callout UInt32
FilterWeight UInt64

Event ID 10006: Callout Notify Filter Delete

#
Channel
Diagnostic

Fields #

NameDescription
FilterId UInt64
Callout UInt32
FilterWeight UInt64

Event ID 20001: An error was encountered while loading the driver.

#
Channel
Diagnostic

Fields #

NameDescription
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20002: An error was encountered while unloading the driver.

#
Channel
Diagnostic

Fields #

NameDescription
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20003: An error was encountered while registering a callout.

#
Channel
Diagnostic

Fields #

NameDescription
Callout UInt32
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20004: An error was encountered while unregistering a callout.

#
Channel
Diagnostic

Fields #

NameDescription
Callout UInt32
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 20005: An error was encountered in a classify function.

#
Channel
Diagnostic

Fields #

NameDescription
Callout UInt32
ErrorMessage UnicodeString
NTSTATUS UInt32

Event ID 60011: The Transport Layer Message for IPv4.

#
Channel
Diagnostic

Description

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress UInt32
DestinationAddress UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ByteLength UInt16
MessageFrame Binary

Event ID 60012: The Transport Layer Message for IPv4.

#
Channel
Diagnostic

Description

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv4. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress UInt32
DestinationAddress UInt32
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ByteLength UInt16
MessageFrame Binary

Event ID 60021: The Transport Layer Message for IPv6.

#
Channel
Diagnostic

Description

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress Binary
DestinationAddress Binary
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ByteLength UInt16
MessageFrame Binary

Event ID 60022: The Transport Layer Message for IPv6.

#
Channel
Diagnostic

Description

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Message #

The Transport Layer Message for IPv6. The Transport header is in the MessageFrame.

Fields #

NameDescription
SourceAddress Binary
DestinationAddress Binary
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ByteLength UInt16
MessageFrame Binary

Event ID 60031: The ALE Layer Message for IPv4.

#
Channel
Diagnostic

Fields #

NameDescription
SourceAddress UInt32
DestinationAddress UInt32
SourcePort UInt16
DestinationPort UInt16
Luid UInt64
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ProcessId UInt64
ByteLength UInt16
ProcessPath Binary

Event ID 60041: The Transport Layer Message for IPv6.

#
Channel
Diagnostic

Fields #

NameDescription
SourceAddress Binary
DestinationAddress Binary
SourcePort UInt16
DestinationPort UInt16
Luid UInt64
Direction UInt8
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
Protocol UInt8
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
FlowHandle UInt64
ProcessId UInt64
ByteLength UInt16
ProcessPath Binary

Event ID 60050: A packet has been discarded.

#
Channel
Diagnostic

Fields #

NameDescription
DiscardModule UInt8
DiscardReason UInt32
DiscardFilterID UInt64

Provenance

ETW provider GUID c22d1b14-c242-49de-9f17-1d76b8b9c458

Defined in WFPCapture.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB