Microsoft-Windows-BitLocker-DrivePreparationTool
16 events across 2 channels
Event ID 1: A problem occurred while running the BitLocker Drive Preparation Tool.
#Event ID 2: A problem occurred while running the BitLocker Drive Preparation Tool.
#Event ID 3: A problem occurred while running the BitLocker Drive Preparation Tool.
#Event ID 4: A problem occurred while running the BitLocker Drive Preparation Tool.
#Event ID 5: A problem occurred while running the BitLocker Drive Preparation Tool.
#Event ID 256: Warning Code: Warning_Code.
#Event ID 512: The BitLocker Drive Configuration Tool successfully completed.
#Description
The BitLocker Drive Configuration Tool successfully completed. The target hard disk is ready for BitLocker.
Message #
Event ID 4096: Found a candidate volume for shrink or merge.
#Description
Found a candidate volume for shrink or merge.
Message #
Fields #
| Name | Description |
|---|---|
Shrinkable Boolean | |
ContainsWinRE Boolean | |
VolumeName UnicodeString | |
VolumeSize UInt64 | |
VolumeFreeSpace UInt64 | |
VolumeMaxShrinkSize UInt64 | |
VolumeFlags HexInt32 | |
DriveLetter UnicodeString | |
DiskNumber UInt32 | |
PartitionNumber UInt32 |
Event ID 4097: Found an unallocated extent large enough for the requested size.
#Event ID 4098: Disk extent located on the hard disk containing the System Drive.
#Event ID 4099: Command-line parameters for the BitLocker Drive Preparation Tool.
#Description
Command-line parameters for the BitLocker Drive Preparation Tool.
Message #
Fields #
| Name | Description |
|---|---|
RawCommandLine UnicodeString | |
ShowUsage Boolean | |
DisplayDriveInfo Boolean | |
TargetDriveLetter UnicodeString | |
TargetAction UInt32 | |
NewSystemDriveLetter UnicodeString | |
ShrinkSize Int64 | |
QuietMode Boolean | |
AutoRestart Boolean |
Event ID 4100: Drive will shrink and new active drive PartitionNumber will be created.
#Event ID 4101: New drive ExtentOffset will be created from unallocated space.
#Event ID 4102: Drive will be set as the new system drive Volume Name.
#Event ID 4103: Detected Windows Recovery Environment volume Volume Path.
#Event ID 4104: A volume failed to meet the requirements for a target volume.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 632f767e-0ec3-47b9-ba1c-a0e62a74728a
Defined in BdeHdCfgLib.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02