Microsoft-Windows-FileHistory-Engine

19 events across 2 channels

Event ID 1: UsnJournalScanStart

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
UsnJournalScan
Opcode
Start

Event ID 2: UsnJournalScanStop

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
UsnJournalScan
Opcode
Stop

Event ID 3: BackupOneFileStart

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
BackupOneFile
Opcode
Start

Fields #

NameDescription
SourcePath UnicodeString
DestPath UnicodeString
Size Int64

Event ID 4: BackupOneFileStop

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
BackupOneFile
Opcode
Stop

Fields #

NameDescription
SourcePath UnicodeString
DestPath UnicodeString
Size Int64

Event ID 5: BackupAllFilesStart

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
BackupAllFiles
Opcode
Start

Event ID 6: BackupAllFilesStop

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
BackupAllFiles
Opcode
Stop

Fields #

NameDescription
TotalSize Int64
TotalFiles UInt64

Event ID 7: CatalogFlushStart

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
CatalogFlush
Opcode
Start

Event ID 8: CatalogFlushStop

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
CatalogFlush
Opcode
Stop

Event ID 9: BackupSizeQuotaChange

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
BackupSizeQuotaChange

Fields #

NameDescription
OldQuota UInt64
NewQuota UInt64

Event ID 10: UsnEventProcessingStart

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
UsnEventProcessing
Opcode
Start

Event ID 11: UsnEventProcessingStop

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
UsnEventProcessing
Opcode
Stop

Event ID 12: ScanAndBackupStart

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
ScanAndBackup
Opcode
Start

Event ID 13: ScanAndBackupStop

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
Debug
Task
ScanAndBackup
Opcode
Stop

Event ID 100: File was not backed up due to its full path exceeding MAX_PATH limit or containing unsupported characters.

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
BackupLog
Opcode
Info

Description

File was not backed up due to its full path exceeding MAX_PATH limit or containing unsupported characters.

Message #

File was not backed up due to its full path exceeding MAX_PATH limit or containing unsupported characters:

%1

If you want it to be protected, try using different directory and file names.

Fields #

NameDescription
Path UnicodeString

Event ID 101: File/directory was not backed up due to being encrypted or insufficient permissions.

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
BackupLog
Opcode
Info

Description

File/directory was not backed up due to being encrypted or insufficient permissions.

Message #

File/directory was not backed up due to being encrypted or insufficient permissions:

%1

If you want it to be protected, remove encryption or ask your system administrator to give you access to this file/directory.

Fields #

NameDescription
Path UnicodeString

Event ID 102: File was not backed up due to an error.

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
BackupLog
Opcode
Info

Description

File was not backed up due to an error.

Message #

File was not backed up due to an error:

%1

Windows will not attempt to back up the file again, unless it is modified.

Fields #

NameDescription
Path UnicodeString
Hr UInt32

Event ID 103: File was not backed up due to an error.

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
BackupLog
Opcode
Info

Description

File was not backed up due to an error.

Message #

File was not backed up due to an error:

%1

Windows will attempt to back up the file at a later time.

Fields #

NameDescription
Path UnicodeString
Hr UInt32

Event ID 104: File was not backed up due to being open by an application.

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
BackupLog
Opcode
Info

Description

File was not backed up due to being open by an application.

Message #

File was not backed up due to being open by an application:

%1

Windows will attempt to back up the file at a later time.

Fields #

NameDescription
Path UnicodeString

Event ID 105: File was successfully backed up.

#
Provider
Microsoft-Windows-FileHistory-Engine
Channel
BackupLog
Opcode
Info

Description

File was successfully backed up.

Message #

File was successfully backed up:

%1

Fields #

NameDescription
Path UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID b447b4de-7780-11e0-ada3-18a90531a85a

Defined in fhsvc.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads