Microsoft-Windows-HAL

EventTitleChannelSampleRule
1Initialization of the High Precision Event Timer failed due to a BIOS …SystemNN
2Initialization of the High Precision Event Timer failed due to unsupported …SystemNN
3Initialization of the High Precision Event Timer failed due to an interrupt …SystemNN
4Due to an unexpected condition, the operating system will use another available …SystemNN
5Due to an expected condition, the operating system will use another available …DebugNN
7The processor cycle counter on processor TargetProcessor has been probed by …DebugNN
8The processor's cycle counters have been successfully synchronized from …DebugNN
9The processor cycle counter on processor TargetProcessor was synchronized …DebugNN
10The synchronization of the processor's cycle counters was not able to …DebugNN
11The High Precision Event Timer failed to deliver message signalled interrupts.SystemNN
12The platform firmware has corrupted memory across the previous system power …SystemNN
13The system watchdog timer was triggered.SystemNN
14The watchdog wake timer was triggered.DebugNN
15The iommu has detected an error.SystemNN
16IOMMU fault reporting has been initialized.SystemYN
17The clock interrupt is backed by a platform timer instead of a per-processor …SystemNN
18The performance counter is not readable from user mode.SystemNN
19DMA API failure detected.SystemNN
20The hardware real-time clock was not queried because evaluation of the ACPI Time …SystemNN
21The hardware real-time clock was not set because evaluation of the ACPI Time and …SystemNN

Event ID 1: Initialization of the High Precision Event Timer failed due to a BIOS configuration problem.

#
Channel
System

Message #

Initialization of the High Precision Event Timer failed due to a BIOS configuration problem.
The operating system will use another available platform timer in lieu of the High Precision Event Timer.

Contact your system vendor for technical assistance.
Initialization status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 2: Initialization of the High Precision Event Timer failed due to unsupported hardware.

#
Channel
System

Message #

Initialization of the High Precision Event Timer failed due to unsupported hardware.
The operating system will use another available platform timer in lieu of the High Precision Event Timer.

Initialization status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 3: Initialization of the High Precision Event Timer failed due to an interrupt configuration problem.

#
Channel
System

Message #

Initialization of the High Precision Event Timer failed due to an interrupt configuration problem.
The operating system will use another available platform timer in lieu of the High Precision Event Timer.

It may be possible to address this problem with an updated system BIOS.
Contact your system vendor for technical assistance.
Initialization status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 4: Due to an unexpected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters.

#
Channel
System

Description

Due to an unexpected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters. Status: Status.

Message #

Due to an unexpected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters.  Status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 5: Due to an expected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters.

#
Channel
Debug

Description

Due to an expected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters. Status: Status.

Message #

Due to an expected condition, the operating system will use another available platform timer in lieu of the processor's cycle counters.  Status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 7: The processor cycle counter on processor TargetProcessor has been probed by processor LeadProcessor.

#
Channel
Debug

Description

The processor cycle counter on processor TargetProcessor has been probed by processor LeadProcessor. A counter delta of Delta was detected. The approximate communication delay between these processors was detected to be NopCycles.

Message #

The processor cycle counter on processor %2 has been probed by processor %1.  A counter delta of %3 was detected.  The approximate communication delay between these processors was detected to be %4.

Fields #

NameDescription
LeadProcessor Int32
TargetProcessor Int32
Delta Int64
NopCycles UInt32

Event ID 8: The processor's cycle counters have been successfully synchronized from processor LeadProcessor within acceptable operating thresholds.

#
Channel
Debug

Description

The processor's cycle counters have been successfully synchronized from processor LeadProcessor within acceptable operating thresholds. The maximum positive delta detected was MaximumPositiveDelta and the maximum negative delta was MaximumNegativeDelta. Synchronization executed for Microseconds microseconds.

Message #

The processor's cycle counters have been successfully synchronized from processor %1 within acceptable operating thresholds.  The maximum positive delta detected was %3 and the maximum negative delta was %4.  Synchronization executed for %5 microseconds.

Fields #

NameDescription
LeadProcessor Int32
MaximumPositiveDeltaProcessor Int32
MaximumPositiveDelta Int32
MaximumNegativeDelta Int32
Microseconds Int32

Event ID 9: The processor cycle counter on processor TargetProcessor was synchronized against processor SourceProcessor using an adjustment of Bias cycles on attempt Wave.

#
Channel
Debug

Description

The processor cycle counter on processor TargetProcessor was synchronized against processor SourceProcessor using an adjustment of Bias cycles on attempt Wave. This resulted in a delta of Delta cycles.

Message #

The processor cycle counter on processor %2 was synchronized against processor %1 using an adjustment of %4 cycles on attempt %5.  This resulted in a delta of %3 cycles.

Fields #

NameDescription
SourceProcessor Int32
TargetProcessor Int32
Delta Int64
Bias Int64
Wave UInt32

Event ID 10: The synchronization of the processor's cycle counters was not able to synchronize the processors within acceptable operating thresholds.

#
Channel
Debug

Description

The synchronization of the processor's cycle counters was not able to synchronize the processors within acceptable operating thresholds. Status: Status.

Message #

The synchronization of the processor's cycle counters was not able to synchronize the processors within acceptable operating thresholds.  Status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 11: The High Precision Event Timer failed to deliver message signalled interrupts.

#
Channel
System

Description

The High Precision Event Timer failed to deliver message signalled interrupts. The operating system will fall back to line based interrupts for this timer.

Message #

The High Precision Event Timer failed to deliver message signalled interrupts.  The operating system will fall back to line based interrupts for this timer.
Initialization status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 12: The platform firmware has corrupted memory across the previous system power transition.

#
Channel
System

Description

The platform firmware has corrupted memory across the previous system power transition. Please check for updated firmware for your system.

Message #

The platform firmware has corrupted memory across the previous system power transition.  Please check for updated firmware for your system.

Fields #

NameDescription
Count UInt32
FirstPage UInt32
LastPage UInt32

Event ID 13: The system watchdog timer was triggered.

#
Channel
System

Event ID 14: The watchdog wake timer was triggered.

#
Channel
Debug

Event ID 15: The iommu has detected an error.

#
Channel
System

Description

The IOMMU has detected an error.

Message #

The IOMMU has detected an error.

Device: %1
FaultInformation: %2
FaultReason: %3
ExtendedData: %4

Fields #

NameDescription
SourceId UInt64
FaultInformation UInt64
FaultReason UInt32
ExtendedData UInt64

Event ID 16: IOMMU fault reporting has been initialized.

#
Channel
System
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HAL",
    "guid": "{63D1E632-95CC-4443-9312-AF927761D52A}",
    "event_source_name": "",
    "event_id": 16,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-29T16:32:44.0620303+00:00",
    "event_record_id": 6668,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 8
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The iommu fault reporting has been initialized."
}

Event ID 17: The clock interrupt is backed by a platform timer instead of a per-processor source.

#
Channel
System

Description

The clock interrupt is backed by a platform timer instead of a per-processor source. System performance may be degraded.

Message #

The clock interrupt is backed by a platform timer instead of a per-processor source.  System performance may be degraded.

Event ID 18: The performance counter is not readable from user mode.

#
Channel
System

Description

The performance counter is not readable from user mode. System performance may be degraded.

Message #

The performance counter is not readable from user mode.  System performance may be degraded.

Event ID 19: DMA API failure detected.

#
Channel
System

Message #

DMA API failure detected.

APIIndex: %1
ErrorCode: %2
FailureInformation1: %3
FailureInformation2: %4

Fields #

NameDescription
APIIndex UInt32
ErrorCode UInt32
FailureInformation1 UInt64
FailureInformation2 UInt64

Event ID 20: The hardware real-time clock was not queried because evaluation of the ACPI Time and Alarm Device method failed.

#
Channel
System

Description

The hardware real-time clock was not queried because evaluation of the ACPI Time and Alarm Device method failed. Status: Status.

Message #

The hardware real-time clock was not queried because evaluation of the ACPI Time and Alarm Device method failed.  Status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 21: The hardware real-time clock was not set because evaluation of the ACPI Time and Alarm Device method failed.

#
Channel
System

Description

The hardware real-time clock was not set because evaluation of the ACPI Time and Alarm Device method failed. Status: Status.

Message #

The hardware real-time clock was not set because evaluation of the ACPI Time and Alarm Device method failed.  Status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Provenance

ETW provider GUID 63d1e632-95cc-4443-9312-af927761d52a

Defined in microsoft-windows-hal-events.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB