Microsoft-Windows-DFSN-ServerFilter

Event ID 1: GetReferral Request is received by the DFSN-ServerFilter from SRV

#
Channel
Analytic, Operational
Task
GetReferral
Opcode
RequestReceived

Description

GetReferral Request is received by the DFSN-ServerFilter from SRV.sys.

Message #

GetReferral Request is received by the DFSN-ServerFilter from SRV.sys

Fields #

NameDescription
InputBuffer Pointer
Request Pointer
InputBufferLength UInt16
RequestSize UInt16

Event ID 2: GetReferral Request has been inserted into the Upcall queue and pending processing by the DFSN-ServerService

#
Channel
Analytic, Operational
Task
GetReferral
Opcode
Queued

Fields #

NameDescription
Request Pointer

Event ID 3: GetReferral Response is ready to be returned to SRV

#
Channel
Analytic, Operational
Task
GetReferral
Opcode
ResponseReady

Description

GetReferral Response is ready to be returned to SRV.sys by the DFSN-ServerFilter.

Message #

GetReferral Response is ready to be returned to SRV.sys by the DFSN-ServerFilter

Fields #

NameDescription
Request Pointer
OutputBuffer Pointer
RequestSize UInt16
OutputBufferLength UInt16
Status UInt32NTSTATUS reference

Event ID 4: ProcessUpcall is started by DFSN-ServerService and ready to post response to the request it just processed in DFSN-ServerFilter

#
Channel
Analytic, Operational
Task
ProcessUpcall
Opcode
Start

Fields #

NameDescription
ResponseBuffer Pointer
Request Pointer
ResponseBufferLength UInt16
RequestSize UInt16

Event ID 5: ProcessUpcall has posted the response to the pending Upcall request in DFSN-ServerFilter

#
Channel
Analytic, Operational
Task
ProcessUpcall
Opcode
ResponsePosted

Fields #

NameDescription
Response Pointer
Status UInt32NTSTATUS reference

Event ID 6: ProcessUpcall has dequeued an Upcall request and ready to return to DFSN-ServerService to process the request

#
Channel
Analytic, Operational
Task
ProcessUpcall
Opcode
RequestDequeued

Fields #

NameDescription
Request Pointer
OutputBuffer Pointer
RequestSize UInt16
OutputBufferLength UInt16
Status UInt32NTSTATUS reference

Provenance

ETW provider GUID 5407baea-a563-4e56-819f-7deaa72807ce

Defined in dfs.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB