Microsoft-Windows-ATAPort

EventTitleChannelSampleRule
0Entering Partial state.SATA-LPMNN
1Entering Slumber state.SATA-LPMNN
100Device Enumeration Starts.GeneralYN
101Device Enumeration Completes.GeneralYN
102Transfer Mode Changed.GeneralNN
103Request is Completed.GeneralYN
104Request Timed Out.GeneralNN
105Request Failed because of Transportation Error.GeneralNN
106Device Lost.GeneralNN
107Channel Reset Starts.GeneralNN
108Channel Reset Complets.GeneralNN
109Device Reset Starts.GeneralNN
110Device Reset Complets.GeneralNN
111Channel Start Phase Begins.GeneralNN
112Channel Start Phase Completes.GeneralNN
113Getting device and driver telemetry begins.GeneralNN
113Indicates device failure and the reason for it.DiagnoseNN
114Getting device and driver telemetry completes.GeneralNN
114IO Transfer mode transition (either from DMA to PIO or vice versa).DiagnoseNN
200Request servicing time taken by target device.AnalyticNN
201Request servicing time taken by lower driver stack(s).AnalyticNN
202Dispatching a read request.DiagnoseNN
203Dispatching a write request.DiagnoseNN
204Dispatching a read request.DiagnoseNN
205Dispatching a write request.DiagnoseNN
206Dispatching a read request.DiagnoseNN
207Dispatching a write request.DiagnoseNN
208Completing an IO (read/write) request.DiagnoseNN
209Retrying an IO (read/write) request.DiagnoseNN
210Flush request.DiagnoseNN
211Flush request.DiagnoseNN
212Dispatching an IOCTL.DiagnoseNN
213Dispatching a WMI request.DiagnoseNN
214Completing a non-read/write request.DiagnoseNN
215Dispatching a power request.DiagnoseNN
216Completing a power request.DiagnoseNN
217Dispatching a PnP request.DiagnoseYN
218Completing a PnP request.DiagnoseNN
219Completing a PnP enumeration request.DiagnoseYN
220Performing a queue-related operation.DiagnoseYN
221Dispatching a PassThrough request.DiagnoseNN

Event ID 0: Entering Partial state.

#
Channel
SATA-LPM
Task
LPMstatechange
Opcode
ATAPORT_OPCODE_LPM_POWERSTATE_PARTIAL

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32
Result UInt32

Event ID 1: Entering Slumber state.

#
Channel
SATA-LPM
Task
LPMstatechange
Opcode
ATAPORT_OPCODE_LPM_POWERSTATE_SLUMBER

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32
Result UInt32

Event ID 100: Device Enumeration Starts.

#
Channel
General
Level
Verbose
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_DEV_ENUM_INIT

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-ATAPort/General",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 100,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 14320
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 10,
    "provider": "Microsoft-Windows-ATAPort",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:33:47.874Z",
    "version": 0
  },
  "event_data": {
    "DeviceType": 2,
    "LUN": 0,
    "PathID": 0,
    "PortNumber": 0,
    "SCSIAddressSize": 8,
    "TargetID": 0
  },
  "message": ""
}

Event ID 101: Device Enumeration Completes.

#
Channel
General
Level
Verbose
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_DEV_ENUM_COMPLETE

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-ATAPort/General",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 101,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 14320
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 11,
    "provider": "Microsoft-Windows-ATAPort",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:33:47.874Z",
    "version": 0
  },
  "event_data": {
    "DeviceType": 2,
    "LUN": 0,
    "PathID": 0,
    "PortNumber": 0,
    "SCSIAddressSize": 8,
    "TargetID": 0
  },
  "message": ""
}

Event ID 102: Transfer Mode Changed.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_XFER_MODE_CHANGE

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DMAtoPIO UInt8
StepDownInDMAModes UInt8

Event ID 103: Request is Completed.

#
Channel
General
Also via
realtime ETW trace
Level
Verbose
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_IO_REQUEST_COMPLETE

Fields #

NameDescription
DeviceAddress UInt32
RequestSequence UInt32
QueueTime UInt64
DeviceTime UInt64
MasterIRP Pointer
ActiveRequestCount UInt32
IRBFunction UInt16
DeviceCommand UInt8
IRBStatus UInt8
ATAStatus UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ATAPort",
    "guid": "{CB587AD1-CC35-4EF1-AD93-36CC82A2D319}",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 5,
    "task": 2,
    "opcode": 13,
    "keywords": "0x4000000000000001",
    "time_created": "2026-06-02T05:08:45.428+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 12504,
      "thread_id": 16348
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ATAStatus": 65,
    "ActiveRequestCount": 0,
    "DeviceAddress": 0,
    "DeviceCommand": 0,
    "DeviceTime": 2568,
    "IRBFunction": 512,
    "IRBStatus": 35,
    "MasterIRP": "0x0",
    "QueueTime": 30,
    "RequestSequence": 36473
  },
  "message": "ATAPORT_TASK_GENERAL"
}

Event ID 104: Request Timed Out.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_IO_REQUEST_TIMEOUT

Fields #

NameDescription
DeviceAddress UInt32
RequestSequence UInt32
QueueTime UInt64
DeviceTime UInt64
MasterIRP Pointer
ActiveRequestCount UInt32
IRBFunction UInt16
DeviceCommand UInt8
IRBStatus UInt8
ATAStatus UInt8

Event ID 105: Request Failed because of Transportation Error.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_IO_REQUEST_TRANSPORT_ERROR

Fields #

NameDescription
DeviceAddress UInt32
RequestSequence UInt32
QueueTime UInt64
DeviceTime UInt64
MasterIRP Pointer
ActiveRequestCount UInt32
IRBFunction UInt16
DeviceCommand UInt8
IRBStatus UInt8
ATAStatus UInt8

Event ID 106: Device Lost.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_DEVICE_MISSING

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32

Event ID 107: Channel Reset Starts.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_CHANNEL_RESET_INIT

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32
Result UInt32

Event ID 108: Channel Reset Complets.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_CHANNEL_RESET_COMPLETE

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32
Result UInt32

Event ID 109: Device Reset Starts.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_DEVICE_RESET_INIT

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32
Result UInt32

Event ID 110: Device Reset Complets.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_DEVICE_RESET_COMPLETE

Fields #

NameDescription
SCSIAddressSize UInt32
PortNumber UInt8
PathID UInt8
TargetID UInt8
LUN UInt8
DeviceType UInt32
Result UInt32

Event ID 111: Channel Start Phase Begins.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_CHANNEL_START_INIT

Event ID 112: Channel Start Phase Completes.

#
Channel
General
Task
ATAportGeneral
Opcode
ATAPORT_OPCODE_CHANNEL_START_COMPLETE

Event ID 113: Getting device and driver telemetry begins.

#
Channel
General
Task
Port
Opcode
ATAPORT_OPCODE_GET_TELEMETRY_INIT

Description

Indicates device failure and the reason for it.

Fields #

NameDescription
PortNumber UInt8
BusNumber
TargetId UInt8
LUN UInt8
FailureReason

Event ID 113: Indicates device failure and the reason for it.

#
Channel
Diagnose
Task
Port

Fields #

NameDescription
PortNumber UInt8
BusNumber UInt8
TargetId UInt8
LUN UInt8
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 114: Getting device and driver telemetry completes.

#
Channel
General
Task
Port
Opcode
ATAPORT_OPCODE_GET_TELEMETRY_COMPLETE

Description

IO Transfer mode transition (either from DMA to PIO or vice versa).

Fields #

NameDescription
Irp
TransferModeChangeType

Event ID 114: IO Transfer mode transition (either from DMA to PIO or vice versa).

#
Channel
Diagnose
Task
Port

Fields #

NameDescription
Irp Pointer
TransferModeChangeType UInt8

Event ID 200: Request servicing time taken by target device.

#
Channel
Analytic
Task
Port

Fields #

NameDescription
RequestDurationin100ns UInt64
Irp Pointer
Command UInt8
SrbStatus UInt8
OriginalIrp Pointer

Event ID 201: Request servicing time taken by lower driver stack(s).

#
Channel
Analytic
Task
Port

Fields #

NameDescription
RequestDurationin100ns UInt64
Irp Pointer
Command UInt8
SrbStatus UInt8
OriginalIrp Pointer

Event ID 202: Dispatching a read request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinbytes UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 203: Dispatching a write request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinbytes UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 204: Dispatching a read request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinbytes UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 205: Dispatching a write request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinbytes UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 206: Dispatching a read request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinbytes UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 207: Dispatching a write request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinbytes UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 208: Completing an IO (read/write) request.

#
Channel
Diagnose
Task
Port
Opcode
Completionofrequest.

Fields #

NameDescription
Irp Pointer
NTStatus HexInt32NTSTATUS reference
SrbStatus UInt8
ScsiStatus UInt8
SenseKey UInt8
AddSense UInt8
AddSenseQ UInt8
OriginalIrp Pointer

Event ID 209: Retrying an IO (read/write) request.

#
Channel
Diagnose
Task
Port
Opcode
Retryhandling.

Fields #

NameDescription
Irp Pointer
CurrentRetryCount UInt32

Event ID 210: Flush request.

#
Channel
Diagnose
Task
Port

Fields #

NameDescription
Irp Pointer
Bus UInt8
Target UInt8
LUN UInt8

Event ID 211: Flush request.

#
Channel
Diagnose
Task
Port
Opcode
Completionofrequest.

Fields #

NameDescription
Irp Pointer
NTStatus HexInt32NTSTATUS reference
SrbStatus UInt8
ScsiStatus UInt8
SenseKey UInt8
AddSense UInt8
AddSenseQ UInt8
OriginalIrp Pointer

Event ID 212: Dispatching an IOCTL.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
MajorFunction HexInt32
MinorFunction HexInt32
Parameter HexInt32

Event ID 213: Dispatching a WMI request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
MajorFunction HexInt32
MinorFunction HexInt32
Parameter HexInt32

Event ID 214: Completing a non-read/write request.

#
Channel
Diagnose
Task
Port
Opcode
Completionofrequest.

Fields #

NameDescription
Irp Pointer
Status HexInt32NTSTATUS reference

Event ID 215: Dispatching a power request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
MinorFunction HexInt32
Type UInt8
OldState HexInt32
NewState HexInt32
Action HexInt32
PowerStateContext HexInt32

Event ID 216: Completing a power request.

#
Channel
Diagnose
Task
Port
Opcode
Completionofrequest.

Fields #

NameDescription
Irp Pointer
Status HexInt32NTSTATUS reference

Event ID 217: Dispatching a PnP request.

#
Channel
Diagnose
Level
Informational
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
MinorFunction HexInt32
Type HexInt32
DeviceObject Pointer

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Storage-ATAPort/Diagnose",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 217,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 9208
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 100,
    "provider": "Microsoft-Windows-ATAPort",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:33:47.873Z",
    "version": 0
  },
  "event_data": {
    "DeviceObject": "0xFFFFC807B40E0050",
    "Irp": "0xFFFFC807BE217B50",
    "MinorFunction": "07000000",
    "Type": "00000000"
  },
  "message": ""
}

Event ID 218: Completing a PnP request.

#
Channel
Diagnose
Task
Port
Opcode
Completionofrequest.

Fields #

NameDescription
Irp Pointer
Status HexInt32NTSTATUS reference

Event ID 219: Completing a PnP enumeration request.

#
Channel
Diagnose
Level
Informational
Task
Port
Opcode
Completionofrequest.

Fields #

NameDescription
Irp Pointer
NumberOfChildren UInt32
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-Storage-ATAPort/Diagnose",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 219,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 14320
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 101,
    "provider": "Microsoft-Windows-ATAPort",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:33:47.893Z",
    "version": 0
  },
  "event_data": {
    "Irp": "0xFFFFC807BE217B50",
    "NumberOfChildren": 1,
    "Status": "03010000"
  },
  "message": ""
}

Event ID 220: Performing a queue-related operation.

#
Channel
Diagnose
Also via
realtime ETW trace
Level
Informational
Task
Port
Opcode
Queue_relatedoperation.

Fields #

NameDescription
QueueTag HexInt32
Operation UInt8
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-ATAPort",
    "guid": "{CB587AD1-CC35-4EF1-AD93-36CC82A2D319}",
    "event_source_name": "",
    "event_id": 220,
    "version": 1,
    "level": 4,
    "task": 201,
    "opcode": 106,
    "keywords": "0x2000000800000000",
    "time_created": "2026-06-02T05:08:45.427+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 3380
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Operation": 1,
    "QueueTag": "02000000",
    "Status": "00000000"
  },
  "message": "Port"
}

Event ID 221: Dispatching a PassThrough request.

#
Channel
Diagnose
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
MajorFunction HexInt32
MinorFunction HexInt32
Parameter HexInt32

Provenance

ETW provider GUID {CB587AD1-CC35-4EF1-AD93-36CC82A2D319}

Defined in ataport.sys, the binary that emits these events.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB