Microsoft-Windows-FailoverClustering-CsvFs-Diagnostic
110 events across 3 channels
Event ID 16
#Description
Activity Transfer.
Event ID 256
#Description
Openning file .
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
Volume Pointer | |
VolumeId GUID | |
FileObject Pointer | |
RelativeFileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
DesiredAccess HexInt32 | Process access rights reference |
Options HexInt32 | |
SharedAccess HexInt32 | |
AttributeFlags HexInt32 |
Event ID 256: Openning file FileName.
#Description
Openning file FileName.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
Volume Pointer | |
VolumeId GUID | |
FileObject Pointer | |
RelativeFileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
DesiredAccess HexInt32 | Process access rights reference |
Options HexInt32 | |
SharedAccess HexInt32 | |
AttributeFlags HexInt32 |
Event ID 512
#Description
Closing file object .
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 512: Closing file object FileName.
#Event ID 768
#Description
Cleaning file object .
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 768: Cleaning file object FileName.
#Event ID 848
#Description
All file objects for the stream Scb are invalidated. Reason: 'Reason'.
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
Condition HexInt32 | |
Reason HexInt32 | |
Vcb Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 848: All file objects for the stream Scb are invalidated.
#Description
All file objects for the stream Scb are invalidated. Reason: 'Reason'.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
Condition HexInt32 | |
Reason HexInt32 | |
Vcb Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 864
#Description
All file objects for the stream Scb of file id FileIdHi.FileId are invalidated. Reason: 'Reason'.
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | |
FileIdHi HexInt64 | |
Scb Pointer | |
Condition HexInt32 | |
Reason HexInt32 | |
Volume Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 864: All file objects for the stream Scb of file id FileIdHi.
#Description
All file objects for the stream Scb of file id FileIdHi.FileId are invalidated. Reason: 'Reason'.
Message #
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | |
FileIdHi HexInt64 | |
Scb Pointer | |
Condition HexInt32 | |
Reason HexInt32 | |
Volume Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 885
#Description
File handle FileObject for the stream Ccb is invalidated. Reason: 'Reason'.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Flags HexInt32 | |
Reason HexInt32 | |
Vcb Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 885: File handle FileObject for the stream Ccb is invalidated.
#Description
File handle FileObject for the stream Ccb is invalidated. Reason: 'Reason'.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Flags HexInt32 | |
Reason HexInt32 | |
Vcb Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 896
#Description
File handle FileObject for the stream Scb file id .FileIdHi.FileId is invalidated. Reason: 'Reason'. File name: 'FileName'.
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | |
FileIdHi HexInt64 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Flags HexInt32 | |
Reason HexInt32 | |
Volume Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 896: File handle FileObject for the stream Scb file id .
#Description
File handle FileObject for the stream Scb file id .FileIdHi.FileId is invalidated. Reason: 'Reason'. File name: 'FileName'.
Message #
Fields #
| Name | Description |
|---|---|
FileId HexInt64 | |
FileIdHi HexInt64 | |
FileNameLength UInt16 | |
FileName UnicodeString | |
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Flags HexInt32 | |
Reason HexInt32 | |
Volume Pointer | |
VolumeId GUID | |
Status HexInt32 | NTSTATUS reference |
Event ID 1024
#Description
Query Volume Information completed with status .
Fields #
| Name | Description |
|---|---|
Vcb Pointer | |
BytesPerSector HexInt64 | |
BytesPerCluster HexInt64 | |
BytesPerFileRecordSegment HexInt64 | |
status HexInt32 | NTSTATUS reference |
Event ID 1024: Query Volume Information completed with status status.
#Description
Query Volume Information completed with status status.
Message #
Fields #
| Name | Description |
|---|---|
Vcb Pointer | |
BytesPerSector HexInt64 | |
BytesPerCluster HexInt64 | |
BytesPerFileRecordSegment HexInt64 | |
status HexInt32 | NTSTATUS reference |
Event ID 1280
#Description
Down-level File Object is opened with status .
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
CreateDisposition HexInt32 | |
DesiredAccess HexInt32 | Process access rights reference |
SharedAccess HexInt32 | |
CreateFlags HexInt32 | |
AttributeFlags HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 1280: Down-level File Object FileName is opened with status Status.
#Description
Down-level File Object FileName is opened with status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
CreateDisposition HexInt32 | |
DesiredAccess HexInt32 | Process access rights reference |
SharedAccess HexInt32 | |
CreateFlags HexInt32 | |
AttributeFlags HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 1536
#Description
Down-level File Object is closed.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 1536: Down-level File Object FileName is closed.
#Event ID 1792
#Description
Down-level File Object is released.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 1792: Down-level File Object FileName is released.
#Event ID 2048
#Description
Paging File Object is opened with status .
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
CreateDisposition HexInt32 | |
DesiredAccess HexInt32 | Process access rights reference |
SharedAccess HexInt32 | |
CreateFlags HexInt32 | |
AttributeFlags HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 2048: Paging File Object FileNameLength is opened with status AttributeFlags.
#Description
Paging File Object FileNameLength is opened with status AttributeFlags.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
CreateDisposition HexInt32 | |
DesiredAccess HexInt32 | Process access rights reference |
SharedAccess HexInt32 | |
CreateFlags HexInt32 | |
AttributeFlags HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 2304
#Description
Paging File Object is closed.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 2304: Paging File Object FileNameLength is closed.
#Event ID 4096
#Description
Paging File Object is released.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString |
Event ID 4096: Paging File Object FileNameLength is released.
#Event ID 6144
#Description
Received Byte Range Lock Request . At ; Length ; Key ; Fags .
Fields #
| Name | Description |
|---|---|
File Pointer | |
Scb Pointer | |
Irp Pointer | |
MinorFunction HexInt32 | |
Flags HexInt32 | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
FailImmediately Boolean | |
Exclusive Boolean |
Event ID 6144: Received Byte Range Lock Request MinorFunction.
#Description
Received Byte Range Lock Request MinorFunction. At Offset; Length Length; Key Key; Fags Flags.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | |
Scb Pointer | |
Irp Pointer | |
MinorFunction HexInt32 | |
Flags HexInt32 | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
FailImmediately Boolean | |
Exclusive Boolean |
Event ID 6400
#Description
Completed Byte Range Lock Request . At ; Length ; Key ; Fags .
Fields #
| Name | Description |
|---|---|
File Pointer | |
Scb Pointer | |
Irp Pointer | |
MinorFunction HexInt32 | |
Flags HexInt32 | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
FailImmediately Boolean | |
Exclusive Boolean | |
Status HexInt32 | NTSTATUS reference |
Event ID 6400: Completed Byte Range Lock Request MinorFunction.
#Description
Completed Byte Range Lock Request MinorFunction. At Offset; Length Length; Key Key; Fags Flags.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | |
Scb Pointer | |
Irp Pointer | |
MinorFunction HexInt32 | |
Flags HexInt32 | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
FailImmediately Boolean | |
Exclusive Boolean | |
Status HexInt32 | NTSTATUS reference |
Event ID 8192
#Description
Removed Lock. At ; Length ; Key ; Exclusive .
Fields #
| Name | Description |
|---|---|
File Pointer | |
Irp Pointer | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
Exclusive Boolean | |
Context Pointer |
Event ID 8192: Removed Lock.
#Event ID 8208
#Description
Cleanup Locks. Status . Downlevel status .
Fields #
| Name | Description |
|---|---|
File Pointer | |
Process Pointer | |
Status HexInt32 | NTSTATUS reference |
DownLevelStatus HexInt32 |
Event ID 8208: Cleanup Locks.
#Description
Cleanup Locks. Status Status. Downlevel status DownLevelStatus.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | |
Process Pointer | |
Status HexInt32 | NTSTATUS reference |
DownLevelStatus HexInt32 |
Event ID 8224
#Description
Resume Lock. At ; Length ; Key ; Exclusive . Status .
Fields #
| Name | Description |
|---|---|
File Pointer | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
Exclusive Boolean | |
Status HexInt32 | NTSTATUS reference |
Event ID 8224: Resume Lock.
#Description
Resume Lock. At Offset; Length Length; Key Key; Exclusive Exclusive. Status Status.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
Exclusive Boolean | |
Status HexInt32 | NTSTATUS reference |
Event ID 8272
#Description
Resuming oplock to level completed with status .
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
OplockLevel HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 8272: Resuming oplock to level OplockLevel completed with status Status.
#Description
Resuming oplock to level OplockLevel completed with status Status.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Scb Pointer | |
OplockLevel HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 8448
#Description
Enqueuing Single Client Notify. For File ; Oplock Level is ; Ignore Current Conditions .
Fields #
| Name | Description |
|---|---|
File Pointer | |
Scb Pointer | |
FullPathLength UInt16 | |
FullPath UnicodeString | |
OplockLevel HexInt32 | |
IgnoreCurrentConditions Boolean |
Event ID 8448: Enqueuing Single Client Notify.
#Event ID 8464
#Description
Single Client Notify Completion. For File ; Oplock Level is ; Status ; Is Event Completion .
Fields #
| Name | Description |
|---|---|
File Pointer | |
Scb Pointer | |
FullPathLength UInt16 | |
FullPath UnicodeString | |
OplockLevel HexInt32 | |
Status HexInt32 | NTSTATUS reference |
IsEventCompletion Boolean |
Event ID 8464: Single Client Notify Completion.
#Description
Single Client Notify Completion. For File FullPath; Oplock Level is OplockLevel; Status Status; Is Event Completion IsEventCompletion.
Message #
Fields #
| Name | Description |
|---|---|
File Pointer | |
Scb Pointer | |
FullPathLength UInt16 | |
FullPath UnicodeString | |
OplockLevel HexInt32 | |
Status HexInt32 | NTSTATUS reference |
IsEventCompletion Boolean |
Event ID 8704
#Description
Volume transitioning from to SetDownlevel. Local ; Flags ; CountersName ; Volume target path ; File System target path .
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
CurrentState UInt32 | |
IsLocal Boolean | |
Flags HexInt32 | |
CountersName UnicodeString | |
VolumeTargetPath UnicodeString | |
FsTargetPath UnicodeString | |
EnableCOW Boolean | |
EnableDirectIo Boolean | |
ForceWriteThrough Int32 | |
TargetNodeId Int32 | |
DcmSequenceId UnicodeString | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceLastStateTransition UInt64 | |
Lifetime UInt64 |
Event ID 8704: Volume VolumeId transitioning from CurrentState to SetDownlevel.
#Description
Volume VolumeId transitioning from CurrentState to SetDownlevel. Local IsLocal; Flags Flags; CountersName CountersName; Volume target path VolumeTargetPath; File System target path FsTargetPath.
Message #
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
CurrentState UInt32 | |
IsLocal Boolean | |
Flags HexInt32 | |
CountersName UnicodeString | |
VolumeTargetPath UnicodeString | |
FsTargetPath UnicodeString | |
EnableCOW Boolean | |
EnableDirectIo Boolean | |
ForceWriteThrough Int32 | |
TargetNodeId Int32 | |
DcmSequenceId UnicodeString | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceLastStateTransition UInt64 | |
Lifetime UInt64 |
Event ID 8960
#Description
Volume transitioning from to .
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
CurrentState UInt32 | |
NewState UInt32 | |
DcmSequenceId UnicodeString | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceLastStateTransition UInt64 | |
Lifetime UInt64 |
Event ID 8960: Volume VolumeId transitioning from CurrentState to NewState.
#Event ID 9216
#Description
Volume moved to state . Reason ; Status .
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
State UInt32 | |
Source UInt32 | |
Status HexInt32 | NTSTATUS reference |
DcmSequenceId UnicodeString | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceStateTransitionStart UInt64 | |
Lifetime UInt64 | |
InvalidationReason UInt32 |
Event ID 9216: Volume VolumeId moved to state State.
#Description
Volume VolumeId moved to state State. Reason Source; Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
State UInt32 | |
Source UInt32 | |
Status HexInt32 | NTSTATUS reference |
DcmSequenceId UnicodeString | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceStateTransitionStart UInt64 | |
Lifetime UInt64 | |
InvalidationReason UInt32 |
Event ID 9296
#Description
Volume is autopaused. Status . Source: .
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
CountersName UnicodeString | |
FromDirectIo Boolean | |
Irp Pointer | |
Status HexInt32 | NTSTATUS reference |
Source UInt32 | |
Parameter1 HexInt64 | |
Parameter2 HexInt64 | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceLastStateTransition UInt64 | |
Lifetime UInt64 |
Event ID 9296: Volume VolumeId is autopaused.
#Description
Volume VolumeId is autopaused. Status Status. Source: Source.
Message #
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
CountersName UnicodeString | |
FromDirectIo Boolean | |
Irp Pointer | |
Status HexInt32 | NTSTATUS reference |
Source UInt32 | |
Parameter1 HexInt64 | |
Parameter2 HexInt64 | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceLastStateTransition UInt64 | |
Lifetime UInt64 |
Event ID 9312
#Description
Volume was renamed. New name .
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
CountersName UnicodeString | |
CurrentState UInt32 | |
DcmSequenceId UnicodeString | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceLastStateTransition UInt64 | |
Lifetime UInt64 |
Event ID 9312: Volume was renamed.
#Event ID 9328
#Description
IOs timed out on the volume .
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
Count UInt64 | |
LastUptime UInt64 | |
CurrentDowntime UInt64 | |
TimeSinceStateTransitionStart UInt64 | |
Lifetime UInt64 |
Event ID 9328: Count IOs timed out on the volume VolumeId.
#Event ID 9472
#Description
Start IO on (). Major Code . Minor Code .
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
FileObject Pointer | |
Vcb Pointer | |
Scb Pointer | |
Ccb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
IrpFlags HexInt32 | |
IrpContextFlags HexInt32 | |
MajorFunction HexInt32 | |
MinorFunction HexInt32 | |
IrpSlFlags HexInt32 | |
Control HexInt32 | |
Parameter1 HexInt64 | |
Parameter2 HexInt64 | |
Parameter3 HexInt64 | |
Parameter4 HexInt64 | |
IrpContextFlagsUpper HexInt32 |
Event ID 9472: Start IO Irp on FileObject (FileName).
#Description
Start IO Irp on FileObject (FileName). Major Code MajorFunction. Minor Code MinorFunction.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
FileObject Pointer | |
Vcb Pointer | |
Scb Pointer | |
Ccb Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
IrpFlags HexInt32 | |
IrpContextFlags HexInt32 | |
MajorFunction HexInt32 | |
MinorFunction HexInt32 | |
IrpSlFlags HexInt32 | |
Control HexInt32 | |
Parameter1 HexInt64 | |
Parameter2 HexInt64 | |
Parameter3 HexInt64 | |
Parameter4 HexInt64 | |
IrpContextFlagsUpper HexInt32 |
Event ID 9728
#Description
Completed IO . Status . Information .
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 |
Event ID 9728: Completed IO Irp.
#Description
Completed IO Irp. Status Status. Information Information.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 |
Event ID 9984: Posted IO Irp.
#Event ID 10240: Continue IO Irp.
#Event ID 10496
#Description
Pause IO . Status . Information .
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
IrpContextFlags HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 | |
IrpContextFlagsUpper HexInt32 |
Event ID 10496: Pause IO Irp.
#Description
Pause IO Irp. Status IrpContextFlags. Information Status.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
IrpContextFlags HexInt32 | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 | |
IrpContextFlagsUpper HexInt32 |
Event ID 12288: Resume IO Irp.
#Event ID 12320
#Description
Direct IO . Status . Information . Duration 100s nanoseconds.
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 | |
Duration HexInt64 | |
RedirectionReason HexInt32 |
Event ID 12320: Direct IO Irp.
#Description
Direct IO Irp. Status Status. Information Information. Duration Duration 100s nanoseconds.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 | |
Duration HexInt64 | |
RedirectionReason HexInt32 |
Event ID 12336
#Description
Redirect IO . Status . Information . Duration 100s nanoseconds.
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 | |
Duration HexInt64 | |
RedirectionReason HexInt32 |
Event ID 12336: Redirect IO Irp.
#Description
Redirect IO Irp. Status Status. Information Information. Duration Duration 100s nanoseconds.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
IrpContext Pointer | |
Status HexInt32 | NTSTATUS reference |
Information HexInt64 | |
Duration HexInt64 | |
RedirectionReason HexInt32 |
Event ID 12368: Current Node Id NodeId.
#Description
Current Node Id NodeId.
Message #
Fields #
| Name | Description |
|---|---|
NodeId Int32 | |
ReportCsvFs Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FailoverClustering-CsvFs-Diagnostic",
"guid": "{6A86AE90-4E9B-4186-B1D1-9CE0E02BCBC1}",
"event_source_name": "",
"event_id": 12368,
"version": 0,
"level": 4,
"task": 11300,
"opcode": 0,
"keywords": 4611686018427388928,
"time_created": "2026-06-13T15:14:00.7018252+00:00",
"event_record_id": 2,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 7992
},
"channel": "Microsoft-Windows-FailoverClustering-CsvFs/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeId": "0",
"ReportCsvFs": "false"
},
"message": "Current Node Id 0."
}
Event ID 12544
#Description
Volume , .
Fields #
| Name | Description |
|---|---|
Volume Pointer | |
VolumeId GUID | |
VpbFlags Int32 | |
State UInt32 | |
CountersName UnicodeString | |
VolumeTargetPath UnicodeString | |
FsTargetPath UnicodeString | |
EnableCOW Boolean | |
EnableDirectIo Boolean | |
ForceWriteThrough Int32 | |
TargetNodeId Int32 |
Event ID 12544: Volume VolumeId, CountersName.
#Event ID 12800
#Fields #
| Name | Description |
|---|---|
Vcb Pointer | |
Scb Pointer | |
ScbState HexInt32 | |
ScbCondition HexInt32 | |
ScbConditionStatus HexInt32 | |
ScbDownlevelOplockLevel HexInt32 | |
FileId HexInt64 | |
Ccb Pointer | |
CcbFlags HexInt32 | |
ShadowFileObject Pointer | |
RealFileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
CreateDisposition HexInt32 | |
DesiredAccess HexInt32 | Process access rights reference |
SharedAccess HexInt32 | |
CreateFlags HexInt32 | |
AttributeFlags HexInt32 | |
FileIdHi HexInt64 |
Event ID 12800: File FileName.
#Message #
Fields #
| Name | Description |
|---|---|
Vcb Pointer | |
Scb Pointer | |
ScbState HexInt32 | |
ScbCondition HexInt32 | |
ScbConditionStatus HexInt32 | |
ScbDownlevelOplockLevel HexInt32 | |
FileId HexInt64 | |
Ccb Pointer | |
CcbFlags HexInt32 | |
ShadowFileObject Pointer | |
RealFileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
CreateDisposition HexInt32 | |
DesiredAccess HexInt32 | Process access rights reference |
SharedAccess HexInt32 | |
CreateFlags HexInt32 | |
AttributeFlags HexInt32 | |
FileIdHi HexInt64 |
Event ID 13056
#Description
Lock. At ; Length ; Key ; Exclusive .
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
File Pointer | |
Process Pointer | |
Offset HexInt64 | |
Length HexInt64 | |
Key HexInt32 | |
Exclusive Boolean | |
Context Pointer |
Event ID 13056: Lock.
#Event ID 16384
#Description
Tunnel operation . Result .
Fields #
| Name | Description |
|---|---|
TunnelOperationCode HexInt32 | |
TunnelActivityId HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 16384: Tunnel operation TunnelOperationCode.
#Description
Tunnel operation TunnelOperationCode. Result status.
Message #
Fields #
| Name | Description |
|---|---|
TunnelOperationCode HexInt32 | |
TunnelActivityId HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 20480
#Description
Stream was flushed and purged from offset , length . Result .
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
FileOffset HexInt64 | |
Length HexInt32 | |
Flags HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 20480: Stream was flushed and purged from offset FileOffset, length Length.
#Description
Stream was flushed and purged from offset FileOffset, length Length. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
FileOffset HexInt64 | |
Length HexInt32 | |
Flags HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 24576
#Description
Stream was flushed from offset , length . Result .
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
FileOffset HexInt64 | |
Length HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 24576: Stream was flushed from offset FileOffset, length Length.
#Description
Stream was flushed from offset FileOffset, length Length. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
FileOffset HexInt64 | |
Length HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 28672
#Description
Stream was purged from offset , length . Result .
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
FileOffset HexInt64 | |
Length HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 28672: Stream was purged from offset FileOffset, length Length.
#Description
Stream was purged from offset FileOffset, length Length. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Scb Pointer | |
FileOffset HexInt64 | |
Length HexInt32 | |
status HexInt32 | NTSTATUS reference |
Event ID 32768
#Description
Volume was purged. Result .
Fields #
| Name | Description |
|---|---|
Vcb Pointer | |
status HexInt32 | NTSTATUS reference |
Event ID 32768: Volume was purged.
#Description
Volume was purged. Result status.
Message #
Fields #
| Name | Description |
|---|---|
Vcb Pointer | |
status HexInt32 | NTSTATUS reference |
Event ID 36864
#Description
Bookmark: .
Fields #
| Name | Description |
|---|---|
Vcb Pointer | |
Scb Pointer | |
FileId HexInt64 | |
Ccb Pointer | |
ShadowFileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
BookmarkLength UInt16 | |
Bookmark UnicodeString | |
FileIdHi HexInt64 |
Event ID 36864: Bookmark: Bookmark.
#Event ID 40960
#Description
Driver loaded.
Fields #
| Name | Description |
|---|---|
MaxLookAsideDepth UInt64 | |
CpuCount UInt64 | |
Status HexInt32 | NTSTATUS reference |
Event ID 40960: Driver loaded.
#Description
Driver loaded.
Message #
Fields #
| Name | Description |
|---|---|
MaxLookAsideDepth UInt64 | |
CpuCount UInt64 | |
Status HexInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FailoverClustering-CsvFs-Diagnostic",
"guid": "{6A86AE90-4E9B-4186-B1D1-9CE0E02BCBC1}",
"event_source_name": "",
"event_id": 40960,
"version": 0,
"level": 4,
"task": 10100,
"opcode": 0,
"keywords": 4611686018427387905,
"time_created": "2026-06-13T15:14:00.7082049+00:00",
"event_record_id": 3,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 7992
},
"channel": "Microsoft-Windows-FailoverClustering-CsvFs/Operational",
"computer": "telemetry-DC-c.cell-c.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"MaxLookAsideDepth": "16",
"CpuCount": "8",
"Status": "0x0"
},
"message": "Driver loaded."
}
Event ID 45056
#Description
Cluster service connected.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
ProcessId Pointer | |
Status HexInt32 | NTSTATUS reference |
Event ID 45056: Cluster service connected.
#Description
Cluster service connected.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
ProcessId Pointer | |
Status HexInt32 | NTSTATUS reference |
Event ID 49152
#Description
Cluster service disconnected.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
ProcessId Pointer |
Event ID 49152: Cluster service disconnected.
#Event ID 53248
#Description
Data section created.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Scb Pointer | |
Ccb Pointer | |
Operation UInt16 | Known values
|
SyncType UInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 53248: Data section created.
#Description
Data section created.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Scb Pointer | |
Ccb Pointer | |
Operation UInt16 | Known values
|
SyncType UInt32 | |
Status HexInt32 | NTSTATUS reference |
Event ID 57344
#Description
Shared Cahce Map Initialized.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Scb Pointer | |
Ccb Pointer |
Event ID 57344: Shared Cahce Map Initialized.
#Event ID 61440
#Description
Shared Cahce Map Uninitialized.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
FileNameLength UInt16 | |
FileName UnicodeString | |
Scb Pointer | |
Ccb Pointer | |
TruncateSize HexInt64 | |
HasEvent Boolean | |
Result Boolean |
Event ID 61440: Shared Cahce Map Uninitialized.
#Event ID 61696
#Description
Capture full payload.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Fcb Pointer | |
FileId HexInt64 | |
FileIdHi HexInt64 | |
StreamId HexInt64 | |
OplockLevel HexInt32 | |
Flags HexInt32 | |
Offset HexInt64 | |
Length HexInt32 | |
Data Binary | |
Status HexInt32 | NTSTATUS reference |
Event ID 61696: Capture full payload.
#Description
Capture full payload.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Fcb Pointer | |
FileId HexInt64 | |
FileIdHi HexInt64 | |
StreamId HexInt64 | |
OplockLevel HexInt32 | |
Flags HexInt32 | |
Offset HexInt64 | |
Length HexInt32 | |
Data Binary | |
Status HexInt32 | NTSTATUS reference |
Event ID 61952
#Description
Capture payload segment.
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Fcb Pointer | |
FileId HexInt64 | |
FileIdHi HexInt64 | |
StreamId HexInt64 | |
OplockLevel HexInt32 | |
Flags HexInt32 | |
Offset HexInt64 | |
Length HexInt32 | |
FragmentOffset HexInt64 | |
FragmentLength HexInt32 | |
Data Binary | |
Status HexInt32 | NTSTATUS reference |
Event ID 61952: Capture payload segment.
#Description
Capture payload segment.
Message #
Fields #
| Name | Description |
|---|---|
FileObject Pointer | |
Ccb Pointer | |
Scb Pointer | |
Fcb Pointer | |
FileId HexInt64 | |
FileIdHi HexInt64 | |
StreamId HexInt64 | |
OplockLevel HexInt32 | |
Flags HexInt32 | |
Offset HexInt64 | |
Length HexInt32 | |
FragmentOffset HexInt64 | |
FragmentLength HexInt32 | |
Data Binary | |
Status HexInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 6a86ae90-4e9b-4186-b1d1-9ce0e02bcbc1
Defined in CsvFs.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02