Microsoft-Windows-FilterManager
14 events across 1 channel
Event ID 1: File System Filter 'DeviceName'.
#Description
File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) unloaded successfully.
Message #
Fields #
| Name | Description |
|---|---|
FinalStatus HexInt32 | |
DeviceVersionMajor UInt32 | |
DeviceVersionMinor UInt32 | |
DeviceNameLength UInt16 | |
DeviceName UnicodeString | |
DeviceTime FILETIME |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FilterManager",
"guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
"event_source_name": "",
"event_id": 1,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:32:53.9491520+00:00",
"event_record_id": 6724,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 1048
},
"channel": "System",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"FinalStatus": "0x0",
"DeviceVersionMajor": "10",
"DeviceVersionMinor": "0",
"DeviceNameLength": "6",
"DeviceName": "CldFlt",
"DeviceTime": "2074-11-09T15:03:12.0000000Z"
},
"message": "File System Filter 'CldFlt' (Version 10.0, 2074-11-09T15:03:12.000000000Z) unloaded successfully."
}
Event ID 2: Name caching for File System Filters has been disabled on volume 'ExtraString'.
#Event ID 3: Filter Manager failed to attach to volume 'ExtraString'.
#Description
Filter Manager failed to attach to volume 'ExtraString'. This volume will be unavailable for filtering until a reboot. The final status was FinalStatus.
Message #
Fields #
| Name | Description |
|---|---|
FinalStatus HexInt32 | |
ExtraStringLength UInt16 | |
ExtraString UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FilterManager",
"guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-03-20T19:05:01.3188675+00:00",
"event_record_id": 3586,
"correlation": {},
"execution": {
"process_id": 3800,
"thread_id": 8480
},
"channel": "System",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"FinalStatus": "0xc03a001c",
"ExtraStringLength": "23",
"ExtraString": "\\Device\\HarddiskVolume6"
},
"message": "Filter Manager failed to attach to volume '\\Device\\HarddiskVolume6'. This volume will be unavailable for filtering until a reboot. The final status was 0xC03A001C."
}
Event ID 4: File System Filter 'DeviceName'.
#Description
File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) failed to attach to volume 'ExtraString'. The filter returned a non-standard final status of FinalStatus. This filter and/or its supporting applications should handle this condition. If this condition persists, contact the vendor.
Message #
Fields #
| Name | Description |
|---|---|
FinalStatus HexInt32 | |
DeviceVersionMajor UInt32 | |
DeviceVersionMinor UInt32 | |
DeviceNameLength UInt16 | |
DeviceName UnicodeString | |
DeviceTime FILETIME | |
ExtraStringLength UInt16 | |
ExtraString UnicodeString |
Event ID 5: File System Filter 'DeviceName'.
#Description
File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) failed to register with Filter Manager. The final status for this operation was FinalStatus.
Message #
Fields #
| Name | Description |
|---|---|
FinalStatus HexInt32 | |
DeviceVersionMajor UInt32 | |
DeviceVersionMinor UInt32 | |
DeviceNameLength UInt16 | |
DeviceName UnicodeString | |
DeviceTime FILETIME |
Event ID 6: File System Filter 'DeviceName'.
#Description
File System Filter 'DeviceName' (DeviceVersionMajor.DeviceVersionMinor, DeviceTime) has successfully loaded and registered with Filter Manager.
Message #
Fields #
| Name | Description |
|---|---|
FinalStatus HexInt32 | |
DeviceVersionMajor UInt32 | |
DeviceVersionMinor UInt32 | |
DeviceNameLength UInt16 | |
DeviceName UnicodeString | |
DeviceTime FILETIME |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FilterManager",
"guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
"event_source_name": "",
"event_id": 6,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-29T16:32:53.9710076+00:00",
"event_record_id": 6728,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 176
},
"channel": "System",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"FinalStatus": "0x0",
"DeviceVersionMajor": "10",
"DeviceVersionMinor": "0",
"DeviceNameLength": "7",
"DeviceName": "bindflt",
"DeviceTime": "2051-03-04T03:45:47.0000000Z"
},
"message": "File System Filter 'bindflt' (10.0, 2051-03-04T03:45:47.000000000Z) has successfully loaded and registered with Filter Manager."
}
Event ID 7: File System Filter 'DeviceName'.
#Description
File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) failed to start filtering. The final status for this operation was FinalStatus.
Message #
Fields #
| Name | Description |
|---|---|
FinalStatus HexInt32 | |
DeviceVersionMajor UInt32 | |
DeviceVersionMinor UInt32 | |
DeviceNameLength UInt16 | |
DeviceName UnicodeString | |
DeviceTime FILETIME |
Event ID 8: Filter Manager successfully attached to volume 'ExtraString'.
#Event ID 9: Filter Manager failed to attach to file system control device object (CDO) 'ExtraString'.
#Description
Filter Manager failed to attach to file system control device object (CDO) 'ExtraString'. All volumes associated with this file system will be unavailable for filtering until a reboot. The final status was FinalStatus.
Message #
Fields #
| Name | Description |
|---|---|
FinalStatus HexInt32 | |
ExtraStringLength UInt16 | |
ExtraString UnicodeString |
Event ID 10: Filter Manager successfully attached to file system 'ExtraString'.
#Event ID 11: File System Filter 'DeviceName'.
#Description
File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) does not support bypass IO.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
DeviceVersionMajor UInt32 | |
DeviceVersionMinor UInt32 | |
DeviceTime FILETIME | |
SupportedFeatures HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-FilterManager",
"guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
"event_source_name": "",
"event_id": 11,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-05-28T04:02:40.2008732+00:00",
"event_record_id": 1308,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 10520
},
"channel": "System",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"DeviceName": "SysmonDrv",
"DeviceVersionMajor": "0",
"DeviceVersionMinor": "0",
"DeviceTime": "2026-03-25T15:35:43.0000000Z",
"SupportedFeatures": "0x4"
},
"message": "File System Filter 'SysmonDrv' (Version 0.0, 2026-03-25T15:35:43.000000000Z) does not support bypass IO.\r\nSupported features: 0x4."
}
Event ID 12: File System Filter 'Process'.
#Description
File System Filter 'Process' (Version File.Bypass_IO_Operation, Vetoing_Reason) vetoed bypass IO.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
DeviceVersionMajor UInt32 | |
DeviceVersionMinor UInt32 | |
DeviceTime FILETIME | |
ProcessName AnsiString | |
FileName UnicodeString | |
BypassIoOperation UInt32 | |
BypassVetoingReason UnicodeString | |
OperationStatus HexInt32 | NTSTATUS reference |
Event ID 13: Filter Manager failed to load filter attach policy for this volume.
#Description
Filter Manager failed to load filter attach policy for this volume.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
VolumeGuid GUID | |
FsGuid GUID | |
FsDriverNameLength UInt16 | |
FsDriverName UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 14: Filter Manager successfully loaded filter attach policy for this volume.
#Description
Filter Manager successfully loaded filter attach policy for this volume.
Message #
Fields #
| Name | Description |
|---|---|
VolumeNameLength UInt16 | |
VolumeName UnicodeString | |
VolumeGuid GUID | |
FsGuid GUID | |
FsDriverNameLength UInt16 | |
FsDriverName UnicodeString | |
GpAllowStatus HexInt32 | |
GpAllowListLength UInt16 | |
GpAllowList UnicodeString | |
SystemAllowStatus HexInt32 | |
SystemAllowListLength UInt16 | |
SystemAllowList UnicodeString | |
VolumeAllowStatus HexInt32 | |
VolumeAllowListLength UInt16 | |
VolumeAllowList UnicodeString | |
AllowAvFilter Boolean | |
AvPolicyIsFromGp Boolean |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID f3c5e28e-63f6-49c7-a204-e48a1bc4b09d
Defined in fltmgr.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02