Microsoft-Windows-Crashdump
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 1 | Resume capable | Analytic, Operational | N | N |
| 2 | Transfer sizes | Analytic, Operational | N | N |
| 3 | Create dump file | Operational | N | N |
| 4 | Soft restart prepare for early crash dump failed with status Status, failure … | Operational | N | N |
| 5 | Early crash dump support failed to initialize with status Status. | Operational | N | N |
| 6 | Early crash dump support succesfully initialized | Analytic | N | N |
| 7 | Early crash dump is supported by the operating system | Analytic | N | N |
Event ID 3: Create dump file
#Fields #
| Name | Description |
|---|---|
IoSpaceEnabled Boolean | |
PhysicalMemorySizeInBytes UInt64 | |
DumpFileSizeInBytes UInt64 | |
CreateDumpFileDurationInMs UInt64 | |
LargeDumpThresholdGB UInt32 |
Event ID 4: Soft restart prepare for early crash dump failed with status Status, failure point FailurePoint.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
FailurePoint UInt32 |
Event ID 5: Early crash dump support failed to initialize with status Status.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 6: Early crash dump support succesfully initialized
#Event ID 7: Early crash dump is supported by the operating system
#Provenance
ETW provider GUID ecdaacfa-6fe9-477c-b5f0-85b76f8f50aa
Defined in crashdmp.sys, the binary that emits these events.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB