Microsoft-Windows-FileHistory-Catalog

44 events across 1 channel

Event ID 1: AttachStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Attach
Opcode
Start

Fields #

NameDescription
CatalogPath UnicodeString
CatalogPath2 UnicodeString
ReadOnly Int32

Event ID 2: AttachStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Attach
Opcode
Stop

Fields #

NameDescription
CatalogPath UnicodeString
CatalogPath2 UnicodeString
ReadOnly Int32

Event ID 3: DetachStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Detach
Opcode
Start

Event ID 4: DetachStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Detach
Opcode
Stop

Event ID 5: CreateStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Create
Opcode
Start

Fields #

NameDescription
CatalogPath UnicodeString
CatalogPath2 UnicodeString

Event ID 6: CreateStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Create
Opcode
Stop

Fields #

NameDescription
CatalogPath UnicodeString
CatalogPath2 UnicodeString

Event ID 7: AddNamespaceRecordStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
AddNamespaceRecord
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 8: AddNamespaceRecordStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
AddNamespaceRecord
Opcode
Stop

Fields #

NameDescription
Path UnicodeString

Event ID 9: UpdateNamespaceRecordStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
UpdateNamespaceRecord
Opcode
Start

Fields #

NameDescription
id Int32
Path UnicodeString

Event ID 10: UpdateNamespaceRecordStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
UpdateNamespaceRecord
Opcode
Stop

Fields #

NameDescription
id Int32
Path UnicodeString

Event ID 11: GetNamespaceRecordStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
GetNamespaceRecord
Opcode
Start

Fields #

NameDescription
id Int32

Event ID 12: GetNamespaceRecordStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
GetNamespaceRecord
Opcode
Stop

Fields #

NameDescription
id Int32

Event ID 13: AddFileRecordStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
AddFileRecord
Opcode
Start

Fields #

NameDescription
Path UnicodeString

Event ID 14: AddFileRecordStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
AddFileRecord
Opcode
Stop

Fields #

NameDescription
Path UnicodeString

Event ID 15: UpdateFileRecordStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
UpdateFileRecord
Opcode
Start

Fields #

NameDescription
id Int32
Path UnicodeString

Event ID 16: UpdateFileRecordStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
UpdateFileRecord
Opcode
Stop

Fields #

NameDescription
id Int32
Path UnicodeString

Event ID 17: GetFileRecordStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
GetFileRecord
Opcode
Start

Fields #

NameDescription
id Int32

Event ID 18: GetFileRecordStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
GetFileRecord
Opcode
Stop

Fields #

NameDescription
id Int32

Event ID 19: FindNsRecordsByFullPathStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindNsRecordsByFullPath
Opcode
Start

Fields #

NameDescription
Path UnicodeString
InitialPosition Int32

Event ID 20: FindNsRecordsByFullPathStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindNsRecordsByFullPath
Opcode
Stop

Fields #

NameDescription
Path UnicodeString
InitialPosition Int32

Event ID 21: FindPointInTimeFolderStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindPointInTimeFolder
Opcode
Start

Fields #

NameDescription
Path UnicodeString
BackupSetId Int32

Event ID 22: FindPointInTimeFolderStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindPointInTimeFolder
Opcode
Stop

Fields #

NameDescription
Path UnicodeString
BackupSetId Int32

Event ID 23: FindNsRecordsByFileRecordIdStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindNsRecordsByFileRecordId
Opcode
Start

Fields #

NameDescription
FileRecordId Int32

Event ID 24: FindNsRecordsByFileRecordIdStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindNsRecordsByFileRecordId
Opcode
Stop

Fields #

NameDescription
FileRecordId Int32

Event ID 25: FindFileRecordsByStateStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindFileRecordsByState
Opcode
Start

Fields #

NameDescription
State Int32
Sort Int32

Event ID 26: FindFileRecordsByStateStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindFileRecordsByState
Opcode
Stop

Fields #

NameDescription
State Int32
Sort Int32

Event ID 27: FindLibrariesTimelineStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindLibrariesTimeline
Opcode
Start

Event ID 28: FindLibrariesTimelineStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindLibrariesTimeline
Opcode
Stop

Event ID 29: FindLibraryTimelineStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindLibraryTimeline
Opcode
Start

Fields #

NameDescription
LibraryName UnicodeString

Event ID 30: FindLibraryTimelineStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindLibraryTimeline
Opcode
Stop

Fields #

NameDescription
LibraryName UnicodeString

Event ID 31: FindPointInTimeLibrariesStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindPointInTimeLibraries
Opcode
Start

Fields #

NameDescription
BackupSetId Int32

Event ID 32: FindPointInTimeLibrariesStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindPointInTimeLibraries
Opcode
Stop

Fields #

NameDescription
BackupSetId Int32

Event ID 33: FindPointInTimeLibraryStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindPointInTimeLibrary
Opcode
Start

Fields #

NameDescription
LibraryName UnicodeString
BackupSetId Int32

Event ID 34: FindPointInTimeLibraryStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindPointInTimeLibrary
Opcode
Stop

Fields #

NameDescription
LibraryName UnicodeString
BackupSetId Int32

Event ID 35: FindAllLibraryRecordsStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindAllLibraryRecords
Opcode
Start

Event ID 36: FindAllLibraryRecordsStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindAllLibraryRecords
Opcode
Stop

Event ID 37: ReattachStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Reattach
Opcode
Start

Event ID 38: ReattachStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
Reattach
Opcode
Stop

Event ID 39: MoveNextStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
MoveNext
Opcode
Start

Fields #

NameDescription
IteratorName UnicodeString

Event ID 40: MoveNextStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
MoveNext
Opcode
Stop

Fields #

NameDescription
IteratorName UnicodeString

Event ID 41: MovePreviousStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
MovePrevious
Opcode
Start

Fields #

NameDescription
IteratorName UnicodeString

Event ID 42: MovePreviousStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
MovePrevious
Opcode
Stop

Fields #

NameDescription
IteratorName UnicodeString

Event ID 43: FindNsRecordsByTVisibleStart

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindNsRecordsByTVisible
Opcode
Start

Fields #

NameDescription
BackupSetId Int32

Event ID 44: FindNsRecordsByTVisibleStop

#
Provider
Microsoft-Windows-FileHistory-Catalog
Channel
Debug
Task
FindNsRecordsByTVisible
Opcode
Stop

Fields #

NameDescription
BackupSetId Int32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID b447b4dc-7780-11e0-ada3-18a90531a85a

Defined in fhsvc.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads