Microsoft-Windows-FilterManager

14 events across 1 channel

Event ID 1: File System Filter 'DeviceName'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System
Level
Informational

Description

File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) unloaded successfully.

Message #

File System Filter '%5' (Version %2.%3, %6) unloaded successfully.

Fields #

NameDescription
FinalStatus HexInt32
DeviceVersionMajor UInt32
DeviceVersionMinor UInt32
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceTime FILETIME

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FilterManager",
    "guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:53.9491520+00:00",
    "event_record_id": 6724,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 1048
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "FinalStatus": "0x0",
    "DeviceVersionMajor": "10",
    "DeviceVersionMinor": "0",
    "DeviceNameLength": "6",
    "DeviceName": "CldFlt",
    "DeviceTime": "2074-11-09T15:03:12.0000000Z"
  },
  "message": "File System Filter 'CldFlt' (Version 10.0, ‎2074‎-‎11‎-‎09T15:03:12.000000000Z) unloaded successfully."
}

Event ID 2: Name caching for File System Filters has been disabled on volume 'ExtraString'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

Name caching for File System Filters has been disabled on volume 'ExtraString'.

Message #

Name caching for File System Filters has been disabled on volume '%3'.

Fields #

NameDescription
FinalStatus HexInt32
ExtraStringLength UInt16
ExtraString UnicodeString

Event ID 3: Filter Manager failed to attach to volume 'ExtraString'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System
Level
Error

Description

Filter Manager failed to attach to volume 'ExtraString'. This volume will be unavailable for filtering until a reboot. The final status was FinalStatus.

Message #

Filter Manager failed to attach to volume '%3'.  This volume will be unavailable for filtering until a reboot.  The final status was %1.

Fields #

NameDescription
FinalStatus HexInt32
ExtraStringLength UInt16
ExtraString UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FilterManager",
    "guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-03-20T19:05:01.3188675+00:00",
    "event_record_id": 3586,
    "correlation": {},
    "execution": {
      "process_id": 3800,
      "thread_id": 8480
    },
    "channel": "System",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "FinalStatus": "0xc03a001c",
    "ExtraStringLength": "23",
    "ExtraString": "\\Device\\HarddiskVolume6"
  },
  "message": "Filter Manager failed to attach to volume '\\Device\\HarddiskVolume6'.  This volume will be unavailable for filtering until a reboot.  The final status was 0xC03A001C."
}

Event ID 4: File System Filter 'DeviceName'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) failed to attach to volume 'ExtraString'. The filter returned a non-standard final status of FinalStatus. This filter and/or its supporting applications should handle this condition. If this condition persists, contact the vendor.

Message #

File System Filter '%5' (Version %2.%3, %6) failed to attach to volume '%8'.  The filter returned a non-standard final status of %1.  This filter and/or its supporting applications should handle this condition.  If this condition persists, contact the vendor.

Fields #

NameDescription
FinalStatus HexInt32
DeviceVersionMajor UInt32
DeviceVersionMinor UInt32
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceTime FILETIME
ExtraStringLength UInt16
ExtraString UnicodeString

Event ID 5: File System Filter 'DeviceName'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) failed to register with Filter Manager. The final status for this operation was FinalStatus.

Message #

File System Filter '%5' (Version %2.%3, %6) failed to register with Filter Manager.  The final status for this operation was %1.

Fields #

NameDescription
FinalStatus HexInt32
DeviceVersionMajor UInt32
DeviceVersionMinor UInt32
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceTime FILETIME

Event ID 6: File System Filter 'DeviceName'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System
Level
Informational
Collection Priority
Recommended (NSA)

Description

File System Filter 'DeviceName' (DeviceVersionMajor.DeviceVersionMinor, DeviceTime) has successfully loaded and registered with Filter Manager.

Message #

File System Filter '%5' (%2.%3, %6) has successfully loaded and registered with Filter Manager.

Fields #

NameDescription
FinalStatus HexInt32
DeviceVersionMajor UInt32
DeviceVersionMinor UInt32
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceTime FILETIME

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FilterManager",
    "guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
    "event_source_name": "",
    "event_id": 6,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:53.9710076+00:00",
    "event_record_id": 6728,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 176
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "FinalStatus": "0x0",
    "DeviceVersionMajor": "10",
    "DeviceVersionMinor": "0",
    "DeviceNameLength": "7",
    "DeviceName": "bindflt",
    "DeviceTime": "2051-03-04T03:45:47.0000000Z"
  },
  "message": "File System Filter 'bindflt' (10.0, ‎2051‎-‎03‎-‎04T03:45:47.000000000Z) has successfully loaded and registered with Filter Manager."
}

Event ID 7: File System Filter 'DeviceName'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) failed to start filtering. The final status for this operation was FinalStatus.

Message #

File System Filter '%5' (Version %2.%3, %6) failed to start filtering.  The final status for this operation was %1.

Fields #

NameDescription
FinalStatus HexInt32
DeviceVersionMajor UInt32
DeviceVersionMinor UInt32
DeviceNameLength UInt16
DeviceName UnicodeString
DeviceTime FILETIME

Event ID 8: Filter Manager successfully attached to volume 'ExtraString'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

Filter Manager successfully attached to volume 'ExtraString'.

Message #

Filter Manager successfully attached to volume '%3'.

Fields #

NameDescription
FinalStatus HexInt32
ExtraStringLength UInt16
ExtraString UnicodeString

Event ID 9: Filter Manager failed to attach to file system control device object (CDO) 'ExtraString'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

Filter Manager failed to attach to file system control device object (CDO) 'ExtraString'. All volumes associated with this file system will be unavailable for filtering until a reboot. The final status was FinalStatus.

Message #

Filter Manager failed to attach to file system control device object (CDO) '%3'.  All volumes associated with this file system will be unavailable for filtering until a reboot. The final status was %1.

Fields #

NameDescription
FinalStatus HexInt32
ExtraStringLength UInt16
ExtraString UnicodeString

Event ID 10: Filter Manager successfully attached to file system 'ExtraString'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

Filter Manager successfully attached to file system 'ExtraString'.

Message #

Filter Manager successfully attached to file system '%3'.

Fields #

NameDescription
FinalStatus HexInt32
ExtraStringLength UInt16
ExtraString UnicodeString

Event ID 11: File System Filter 'DeviceName'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System
Level
Warning

Description

File System Filter 'DeviceName' (Version DeviceVersionMajor.DeviceVersionMinor, DeviceTime) does not support bypass IO.

Message #

File System Filter '%1' (Version %2.%3, %4) does not support bypass IO.
Supported features: %5.

Fields #

NameDescription
DeviceName UnicodeString
DeviceVersionMajor UInt32
DeviceVersionMinor UInt32
DeviceTime FILETIME
SupportedFeatures HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-FilterManager",
    "guid": "{F3C5E28E-63F6-49C7-A204-E48A1BC4B09D}",
    "event_source_name": "",
    "event_id": 11,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-28T04:02:40.2008732+00:00",
    "event_record_id": 1308,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 10520
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceName": "SysmonDrv",
    "DeviceVersionMajor": "0",
    "DeviceVersionMinor": "0",
    "DeviceTime": "2026-03-25T15:35:43.0000000Z",
    "SupportedFeatures": "0x4"
  },
  "message": "File System Filter 'SysmonDrv' (Version 0.0, ‎2026‎-‎03‎-‎25T15:35:43.000000000Z) does not support bypass IO.\r\nSupported features: 0x4."
}

Event ID 12: File System Filter 'Process'.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

File System Filter 'Process' (Version File.Bypass_IO_Operation, Vetoing_Reason) vetoed bypass IO.

Message #

File System Filter '%1' (Version %2.%3, %4) vetoed bypass IO.

     Process: %5
     File: %6
     Bypass IO Operation: %7
     Vetoing Reason: %8
     Operation Status: %9

Fields #

NameDescription
DeviceName UnicodeString
DeviceVersionMajor UInt32
DeviceVersionMinor UInt32
DeviceTime FILETIME
ProcessName AnsiString
FileName UnicodeString
BypassIoOperation UInt32
BypassVetoingReason UnicodeString
OperationStatus HexInt32NTSTATUS reference

Event ID 13: Filter Manager failed to load filter attach policy for this volume.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

Filter Manager failed to load filter attach policy for this volume.

Message #

Filter Manager failed to load filter attach policy for this volume.

     Volume name: %2
     Volume GUID: %3
     File system GUID: %4
     File system driver: %6
     Status: %7

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString
VolumeGuid GUID
FsGuid GUID
FsDriverNameLength UInt16
FsDriverName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 14: Filter Manager successfully loaded filter attach policy for this volume.

#
Provider
Microsoft-Windows-FilterManager
Channel
System

Description

Filter Manager successfully loaded filter attach policy for this volume.

Message #

Filter Manager successfully loaded filter attach policy for this volume.

     Volume name: %2
     Volume GUID: %3
     File system GUID: %4
     File system driver: %6

     GpAllowStatus: %7
     SystemAllowStatus: %10
     VolumeAllowStatus: %13
     Allow antivirus filter: %16
     Antivirus policy is from group policy: %17

Fields #

NameDescription
VolumeNameLength UInt16
VolumeName UnicodeString
VolumeGuid GUID
FsGuid GUID
FsDriverNameLength UInt16
FsDriverName UnicodeString
GpAllowStatus HexInt32
GpAllowListLength UInt16
GpAllowList UnicodeString
SystemAllowStatus HexInt32
SystemAllowListLength UInt16
SystemAllowList UnicodeString
VolumeAllowStatus HexInt32
VolumeAllowListLength UInt16
VolumeAllowList UnicodeString
AllowAvFilter Boolean
AvPolicyIsFromGp Boolean

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID f3c5e28e-63f6-49c7-a204-e48a1bc4b09d

Defined in fltmgr.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads