Microsoft-Windows-CloudFiles-Filter
4 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | CLDFLT driver entry failed. | Operational | N |
| 2 | CLDFLT registration succeeded | Operational | Y |
| 3 | CLDFLT failed to attach to volume 'VolumeName' with error message: NTStatus. | Operational | N |
| 4 | CLDFLT unload succeeded | Operational | N |
Event ID 1: CLDFLT driver entry failed.
#Description
CLDFLT driver entry failed. Error message: ErrorMsg, Error code: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
ErrorMsg UnicodeString | |
NTStatus HexInt32 | NTSTATUS reference |
Event ID 2: CLDFLT registration succeeded
#Description
CLDFLT registration succeeded.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-CloudFiles-Filter",
"event_id": 2,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T19:31:57.0493335+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-CloudFiles-Filter"
},
"event_data": {}
}
Event ID 3: CLDFLT failed to attach to volume 'VolumeName' with error message: NTStatus.
#Description
CLDFLT failed to attach to volume 'VolumeName' with error message: NTStatus.
Message #
Fields #
| Name | Description |
|---|---|
NTStatus HexInt32 | NTSTATUS reference |
VolumeNameLength UInt16 | |
VolumeName UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 4580bb06-baed-5b62-a4d5-92fa7156e7db
Defined in cldflt.sys, the binary that emits these events.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02