Microsoft-Windows-Crashdump

9 events across 2 channels

Event ID 1: Resume capable

#
Provider
Microsoft-Windows-Crashdump
Channel
Analytic
Task
Resumecapablesettings
Opcode
OpCodeResumeCapable

Description

Resume capable.

Message #

Resume capable

Fields #

NameDescription
ResumeCapable Boolean
ReasonCodes UInt32

Event ID 1: Resume capable

#
Provider
Microsoft-Windows-Crashdump
Channel
Operational
Task
Resumecapablesettings
Opcode
OpCodeResumeCapable

Description

Resume capable.

Message #

Resume capable

Fields #

NameDescription
ResumeCapable Boolean
ReasonCodes UInt32

Event ID 2: Transfer sizes

#
Provider
Microsoft-Windows-Crashdump
Channel
Analytic
Task
Transfersizesettings
Opcode
OpCodeTransferSizes

Description

Transfer sizes.

Message #

Transfer sizes

Fields #

NameDescription
Minimum UInt32
Maximum UInt32

Event ID 2: Transfer sizes

#
Provider
Microsoft-Windows-Crashdump
Channel
Operational
Task
Transfersizesettings
Opcode
OpCodeTransferSizes

Description

Transfer sizes.

Message #

Transfer sizes

Fields #

NameDescription
Minimum UInt32
Maximum UInt32

Event ID 3: Create dump file

#
Provider
Microsoft-Windows-Crashdump
Channel
Operational
Task
Createdumpfilesettings
Opcode
OpCodeCreateDumpFile

Description

Create dump file.

Message #

Create dump file

Fields #

NameDescription
IoSpaceEnabled Boolean
PhysicalMemorySizeInBytes UInt64
DumpFileSizeInBytes UInt64
CreateDumpFileDurationInMs UInt64
LargeDumpThresholdGB UInt32

Event ID 4: Soft restart prepare for early crash dump failed with status Status, failure point FailurePoint.

#
Provider
Microsoft-Windows-Crashdump
Channel
Operational
Task
EarlyCrashDump
Opcode
PrepareFailure

Description

Soft restart prepare for early crash dump failed with status Status, failure point FailurePoint.

Message #

Soft restart prepare for early crash dump failed with status %1, failure point %2

Fields #

NameDescription
Status UInt32NTSTATUS reference
FailurePoint UInt32

Event ID 5: Early crash dump support failed to initialize with status Status.

#
Provider
Microsoft-Windows-Crashdump
Channel
Operational
Task
EarlyCrashDump
Opcode
InitializationFailure

Description

Early crash dump support failed to initialize with status Status.

Message #

Early crash dump support failed to initialize with status %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6: Early crash dump support succesfully initialized

#
Provider
Microsoft-Windows-Crashdump
Channel
Analytic
Task
EarlyCrashDump
Opcode
Initialized

Description

Early crash dump support succesfully initialized.

Message #

Early crash dump support succesfully initialized

Event ID 7: Early crash dump is supported by the operating system

#
Provider
Microsoft-Windows-Crashdump
Channel
Analytic
Task
EarlyCrashDump
Opcode
Supported

Description

Early crash dump is supported by the operating system.

Message #

Early crash dump is supported by the operating system

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID ecdaacfa-6fe9-477c-b5f0-85b76f8f50aa

Defined in crashdmp.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads