Microsoft-Windows-FileHistory-Engine
19 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | UsnJournalScanStart | Debug | N |
| 2 | UsnJournalScanStop | Debug | N |
| 3 | BackupOneFileStart | Debug | N |
| 4 | BackupOneFileStop | Debug | N |
| 5 | BackupAllFilesStart | Debug | N |
| 6 | BackupAllFilesStop | Debug | N |
| 7 | CatalogFlushStart | Debug | N |
| 8 | CatalogFlushStop | Debug | N |
| 9 | BackupSizeQuotaChange | Debug | N |
| 10 | UsnEventProcessingStart | Debug | N |
| 11 | UsnEventProcessingStop | Debug | N |
| 12 | ScanAndBackupStart | Debug | N |
| 13 | ScanAndBackupStop | Debug | N |
| 100 | File was not backed up due to its full path exceeding MAX_PATH limit or … | BackupLog | N |
| 101 | File/directory was not backed up due to being encrypted or insufficient … | BackupLog | N |
| 102 | File was not backed up due to an error. | BackupLog | N |
| 103 | File was not backed up due to an error. | BackupLog | N |
| 104 | File was not backed up due to being open by an application. | BackupLog | N |
| 105 | File was successfully backed up. | BackupLog | N |
Event ID 1: UsnJournalScanStart
#Event ID 2: UsnJournalScanStop
#Event ID 3: BackupOneFileStart
#Fields #
| Name | Description |
|---|---|
SourcePath UnicodeString | |
DestPath UnicodeString | |
Size Int64 |
Event ID 4: BackupOneFileStop
#Fields #
| Name | Description |
|---|---|
SourcePath UnicodeString | |
DestPath UnicodeString | |
Size Int64 |
Event ID 5: BackupAllFilesStart
#Event ID 7: CatalogFlushStart
#Event ID 8: CatalogFlushStop
#Event ID 10: UsnEventProcessingStart
#Event ID 11: UsnEventProcessingStop
#Event ID 12: ScanAndBackupStart
#Event ID 13: ScanAndBackupStop
#Event ID 100: File was not backed up due to its full path exceeding MAX_PATH limit or containing unsupported characters.
#Event ID 101: File/directory was not backed up due to being encrypted or insufficient permissions.
#Event ID 102: File was not backed up due to an error.
#Event ID 103: File was not backed up due to an error.
#Event ID 104: File was not backed up due to being open by an application.
#Event ID 105: File was successfully backed up.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID b447b4de-7780-11e0-ada3-18a90531a85a
Defined in fhsvc.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02