Microsoft-Windows-Crashdump

Event ID 1: Resume capable

#
Channel
Analytic, Operational
Task
Resumecapablesettings
Opcode
OpCodeResumeCapable

Fields #

NameDescription
ResumeCapable Boolean
ReasonCodes UInt32

Event ID 2: Transfer sizes

#
Channel
Analytic, Operational
Task
Transfersizesettings
Opcode
OpCodeTransferSizes

Fields #

NameDescription
Minimum UInt32
Maximum UInt32

Event ID 3: Create dump file

#
Channel
Operational
Task
Createdumpfilesettings
Opcode
OpCodeCreateDumpFile

Fields #

NameDescription
IoSpaceEnabled Boolean
PhysicalMemorySizeInBytes UInt64
DumpFileSizeInBytes UInt64
CreateDumpFileDurationInMs UInt64
LargeDumpThresholdGB UInt32

Event ID 4: Soft restart prepare for early crash dump failed with status Status, failure point FailurePoint.

#
Channel
Operational
Task
EarlyCrashDump
Opcode
PrepareFailure

Message #

Soft restart prepare for early crash dump failed with status %1, failure point %2

Fields #

NameDescription
Status UInt32NTSTATUS reference
FailurePoint UInt32

Event ID 5: Early crash dump support failed to initialize with status Status.

#
Channel
Operational
Task
EarlyCrashDump
Opcode
InitializationFailure

Message #

Early crash dump support failed to initialize with status %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6: Early crash dump support succesfully initialized

#
Channel
Analytic
Task
EarlyCrashDump
Opcode
Initialized

Event ID 7: Early crash dump is supported by the operating system

#
Channel
Analytic
Task
EarlyCrashDump
Opcode
Supported

Provenance

ETW provider GUID ecdaacfa-6fe9-477c-b5f0-85b76f8f50aa

Defined in crashdmp.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB