Microsoft-Windows-Crashdump
9 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | Resume capable | Analytic | N |
| 1 | Resume capable | Operational | N |
| 2 | Transfer sizes | Analytic | N |
| 2 | Transfer sizes | Operational | N |
| 3 | Create dump file | Operational | N |
| 4 | Soft restart prepare for early crash dump failed with status Status, failure … | Operational | N |
| 5 | Early crash dump support failed to initialize with status Status. | Operational | N |
| 6 | Early crash dump support succesfully initialized | Analytic | N |
| 7 | Early crash dump is supported by the operating system | Analytic | N |
Event ID 1: Resume capable
#Event ID 1: Resume capable
#Event ID 2: Transfer sizes
#Event ID 2: Transfer sizes
#Event ID 3: Create dump file
#Event ID 4: Soft restart prepare for early crash dump failed with status Status, failure point FailurePoint.
#Description
Soft restart prepare for early crash dump failed with status Status, failure point FailurePoint.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
FailurePoint UInt32 |
Event ID 5: Early crash dump support failed to initialize with status Status.
#Description
Early crash dump support failed to initialize with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 6: Early crash dump support succesfully initialized
#Description
Early crash dump support succesfully initialized.
Message #
Event ID 7: Early crash dump is supported by the operating system
#Description
Early crash dump is supported by the operating system.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID ecdaacfa-6fe9-477c-b5f0-85b76f8f50aa
Defined in crashdmp.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02