Microsoft-Windows-Hyper-V-Compute
274 events across 4 channels
Event ID 100: TraceData.
#Event ID 100
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 101: TraceData.
#Event ID 101
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 102: TraceData.
#Event ID 102
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 103: TraceData.
#Event ID 103
#Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 500: Started DM operation add memory.
#Event ID 500: Started DM operation add memory
#Description
Started DM operation add memory. Balancer requested to add pages. (Virtual machine ID ).
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 501: DM operation add memory completed Parameter0 pages were added, time Time s.
#Event ID 501: DM operation add memory completed Parameter0 pages were added, time Time s
#Description
DM operation add memory completed pages were added, time s. (Virtual machine ID ).
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Time UnicodeString | |
Parameter0 UInt64 |
Event ID 502: Started DM operation remove memory.
#Event ID 502: Started DM operation remove memory
#Description
Started DM operation remove memory. Balancer requested to remove pages. (Virtual machine ID ).
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 503: DM operation remove memory completed Parameter0 pages were removed, time Time s.
#Event ID 503: DM operation remove memory completed Parameter0 pages were removed, time Time s
#Description
DM operation remove memory completed pages were removed, time s. (Virtual machine ID ).
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Time UnicodeString | |
Parameter0 UInt64 |
Event ID 504: Started DM operation add memory (SLP).
#Event ID 504: Started DM operation add memory (SLP)
#Description
Started DM operation add memory (SLP). Balancer requested to add pages. (Virtual machine ID ).
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 505: DM operation add memory (SLP) completed Parameter0 pages were added, time Time s.
#Event ID 505: DM operation add memory (SLP) completed Parameter0 pages were added, time Time s
#Description
DM operation add memory (SLP) completed pages were added, time s. (Virtual machine ID ).
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Time UnicodeString | |
Parameter0 UInt64 |
Event ID 506: Virtual machine ID VmId : memory pressure Parameter0.
#Event ID 506: Virtual machine ID VmId : memory pressure
#Description
Virtual machine ID : memory pressure .
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 507: Virtual machine ID VmId : committed memory Parameter0.
#Event ID 507: Virtual machine ID VmId : committed memory
#Description
Virtual machine ID : committed memory .
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 508: Virtual machine ID VmId : available memory Parameter0.
#Event ID 508: Virtual machine ID VmId : available memory
#Description
Virtual machine ID : available memory .
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 509: Virtual machine ID VmId : actual total physical memory Parameter0.
#Event ID 509: Virtual machine ID VmId : actual total physical memory
#Description
Virtual machine ID : actual total physical memory .
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 510: Virtual machine ID VmId : guest visible physical memory Parameter0.
#Event ID 510: Virtual machine ID VmId : guest visible physical memory
#Description
Virtual machine ID : guest visible physical memory .
Fields #
| Name | Description |
|---|---|
VmId UnicodeString | |
Parameter0 UInt64 |
Event ID 511: NUMA node VmId: system average pressure: Parameter0.
#Event ID 511: NUMA node VmId: system average pressure:
#Description
NUMA node : system average pressure: .
Fields #
| Name | Description |
|---|---|
VmId UInt64 | |
Parameter0 UInt64 |
Event ID 512: NUMA node VmId: system available memory: Parameter0 MB.
#Event ID 512: NUMA node VmId: system available memory: Parameter0 MB
#Description
NUMA node : system available memory: MB.
Fields #
| Name | Description |
|---|---|
VmId UInt64 | |
Parameter0 UInt64 |
Event ID 1000: The Host Compute Service is starting.
#Description
The Host Compute Service is starting.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "{17103E3F-3C6E-4677-BB17-3B267EB5BE57}",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T13:54:29.2925566+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 5920,
"thread_id": 3820
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {}
},
"message": "The Host Compute Service is starting."
}
Event ID 1001: The Host Compute Service started successfully.
#Description
The Host Compute Service started successfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 1001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T23:16:25.887020+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 7344,
"thread_id": 8544
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Admin",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {}
},
"message": ""
}
Event ID 1001: The Host Compute Service started successfully
#Description
The Host Compute Service started successfully.
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "{17103E3F-3C6E-4677-BB17-3B267EB5BE57}",
"event_source_name": "",
"event_id": 1001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-06-13T13:54:29.3955289+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 5920,
"thread_id": 3820
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Admin",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {}
},
"message": "The Host Compute Service started successfully."
}
Event ID 1002: The Host Compute Service is shutting down.
#Description
The Host Compute Service is shutting down.
Message #
Event ID 1003: The Host Compute Service shut down successfully.
#Description
The Host Compute Service shut down successfully.
Message #
Event ID 1003: The Host Compute Service shut down successfully
#Description
The Host Compute Service shut down successfully.
Event ID 2000: [VmlEventLog.SystemId] Create compute system, result VmlEventLog.Result.
#Description
[VmlEventLog.SystemId] Create compute system, result VmlEventLog.Result.
Message #
Fields #
| Name | Description |
|---|---|
VmlEventLog.SystemId | |
VmlEventLog.Result | |
SystemId | |
Result |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "{17103E3F-3C6E-4677-BB17-3B267EB5BE57}",
"event_source_name": "",
"event_id": 2000,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T15:12:00.0772694+00:00",
"event_record_id": 30,
"correlation": {},
"execution": {
"process_id": 5920,
"thread_id": 4348
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "23E050BB-12F7-4020-83DB-C1314F6202FB",
"Result": "0xC0370103"
}
},
"message": "[23E050BB-12F7-4020-83DB-C1314F6202FB] Create compute system, result 0xC0370103"
}
Event ID 2001: [VmlEventLog.SystemId] Start compute system, result VmlEventLog.Result.
#Description
[VmlEventLog.SystemId] Start compute system, result VmlEventLog.Result.
Message #
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
Result UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 2001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:31:57.210082+00:00",
"event_record_id": 8,
"correlation": {
"ActivityID": "EC11E65C-B780-44B3-9B69-699C696F1636"
},
"execution": {
"process_id": 9396,
"thread_id": 9428
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "29A7892D-8743-4A3F-85E3-06FE9D7977B4",
"Result": "0xC0370103"
}
},
"message": ""
}
Event ID 2002: [SystemId] Shut down compute system, result Result.
#Event ID 2003: [VmlEventLog.SystemId] Terminate compute system, result VmlEventLog.Result.
#Description
[VmlEventLog.SystemId] Terminate compute system, result VmlEventLog.Result.
Message #
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
Result UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 2003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:09:01.956721+00:00",
"event_record_id": 14,
"correlation": {
"ActivityID": "E036AC8C-7E60-4818-BA86-6545B9F00A66"
},
"execution": {
"process_id": 3904,
"thread_id": 5432
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "2cf3235b-8f46-4ae6-adf2-07dc5259a954",
"Result": "0xC0370103"
}
},
"message": ""
}
Event ID 2004: [VmlEventLog.SystemId] Pause compute system, options 'VmlEventLog.Parameter0', result VmlEventLog.Result.
#Description
[VmlEventLog.SystemId] Pause compute system, options 'VmlEventLog.Parameter0', result VmlEventLog.Result.
Message #
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
Result UnicodeString | |
Parameter0 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 2004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:09:00.848634+00:00",
"event_record_id": 8,
"correlation": {
"ActivityID": "A46EB575-B4A0-4530-869B-825F772695E7"
},
"execution": {
"process_id": 3904,
"thread_id": 5432
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "2cf3235b-8f46-4ae6-adf2-07dc5259a954",
"Result": "0xC0370103",
"Parameter0": "{}"
}
},
"message": ""
}
Event ID 2005: [SystemId] Resume compute system, options 'Parameter0', result Result.
#Event ID 2006: [SystemId] Get compute system properties, query 'Parameter0', result Result.
#Event ID 2007: [VmlEventLog.SystemId] Modify compute system, settings 'VmlEventLog.Parameter0', result VmlEventLog.Result.
#Description
[VmlEventLog.SystemId] Modify compute system, settings 'VmlEventLog.Parameter0', result VmlEventLog.Result.
Message #
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
Result UnicodeString | |
Parameter0 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 2007,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:32:03.625353+00:00",
"event_record_id": 51,
"correlation": {
"ActivityID": "A1ACF3D5-1D8A-4C49-A11D-82377F58D522"
},
"execution": {
"process_id": 9396,
"thread_id": 9428
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "29A7892D-8743-4A3F-85E3-06FE9D7977B4",
"Result": "0x00000000",
"Parameter0": "{\"RequestType\":\"Add\",\"ResourcePath\":\"VirtualMachine/Devices/Scsi/0/Attachments/3\",\"Settings\":{\"AlwaysAllowSparseFiles\":true,\"Path\":\"C:\\\\Users\\\\localuser\\\\AppData\\\\Local\\\\wsl\\\\{4d205ef4-e2d2-4c32-b102-f7572f1907f9}\\\\ext4.vhdx\",\"ReadOnly\":false,\"SupportCompressedVolumes\":true,\"SupportEncryptedFiles\":true,\"Type\":\"VirtualDisk\"}}"
}
},
"message": ""
}
Event ID 2008: [VmlEventLog.SystemId] Query compute system notification, result VmlEventLog.Result, notification VmlEventLog.Parameter0 / VmlEventLog.Parameter1.
#Description
[VmlEventLog.SystemId] Query compute system notification, result VmlEventLog.Result, notification VmlEventLog.Parameter0 / VmlEventLog.Parameter1.
Message #
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
Result UnicodeString | |
Parameter0 UInt32 | |
Parameter1 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 2008,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:32:03.667063+00:00",
"event_record_id": 54,
"correlation": {
"ActivityID": "549D4145-F73A-4A1A-8AB3-9DC4FD21A9CC"
},
"execution": {
"process_id": 9396,
"thread_id": 9432
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "29A7892D-8743-4A3F-85E3-06FE9D7977B4",
"Result": "0x00000000",
"Parameter0": 15,
"Parameter1": "0x00000000"
}
},
"message": ""
}
Event ID 2009: [VmlEventLog.SystemId] Queue system notification: VmlEventLog.Parameter0 / VmlEventLog.Parameter1.
#Description
[VmlEventLog.SystemId] Queue system notification: VmlEventLog.Parameter0 / VmlEventLog.Parameter1.
Message #
Fields #
| Name | Description |
|---|---|
VmlEventLog.SystemId | |
VmlEventLog.Parameter0 | |
VmlEventLog.Parameter1 | |
SystemId | |
Parameter0 | |
Parameter1 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "{17103E3F-3C6E-4677-BB17-3B267EB5BE57}",
"event_source_name": "",
"event_id": 2009,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T15:12:07.4534371+00:00",
"event_record_id": 32,
"correlation": {},
"execution": {
"process_id": 5920,
"thread_id": 8988
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "23E050BB-12F7-4020-83DB-C1314F6202FB",
"Parameter0": "1",
"Parameter1": "0x00000000"
}
},
"message": "[23E050BB-12F7-4020-83DB-C1314F6202FB] Queue system notification: 1 / 0x00000000"
}
Event ID 2010: [SystemId] Create Container, type 'Parameter0', settings 'Parameter1'.
#Event ID 2011: [SystemId] Create Container VM, VM ID Parameter0, result Result.
#Event ID 2012: [SystemId] Create Container template VM, image path 'Parameter2', VP count Parameter0, memory Parameter1 MB.
#Event ID 2013: [SystemId] Using template VM 'Parameter0'.
#Event ID 2014: [VmlEventLog.SystemId] Create Virtual Machine.
#Description
[VmlEventLog.SystemId] Create Virtual Machine.
Message #
Fields #
| Name | Description |
|---|---|
VmlEventLog.SystemId | |
SystemId |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "{17103E3F-3C6E-4677-BB17-3B267EB5BE57}",
"event_source_name": "",
"event_id": 2014,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-06-13T15:11:59.6998015+00:00",
"event_record_id": 28,
"correlation": {},
"execution": {
"process_id": 5920,
"thread_id": 4348
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "23E050BB-12F7-4020-83DB-C1314F6202FB"
}
},
"message": "[23E050BB-12F7-4020-83DB-C1314F6202FB] Create Virtual Machine"
}
Event ID 2015: [SystemId] Add compute system resource, location 'Parameter0', resource 'Parameter1', result Result.
#Event ID 2016: [SystemId] Modify compute system resource, location 'Parameter0', resource 'Parameter1', result Result.
#Event ID 2017: [SystemId] Remove compute system, location 'Parameter0', result Result.
#Event ID 2018: [VmlEventLog.SystemId] Save compute system, options 'VmlEventLog.Parameter0', result VmlEventLog.Result.
#Description
[VmlEventLog.SystemId] Save compute system, options 'VmlEventLog.Parameter0', result VmlEventLog.Result.
Message #
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
Result UnicodeString | |
Parameter0 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 2018,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:09:00.892427+00:00",
"event_record_id": 11,
"correlation": {
"ActivityID": "F671F24A-D38B-4FB5-872A-52DF96BC260A"
},
"execution": {
"process_id": 3904,
"thread_id": 7292
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "2cf3235b-8f46-4ae6-adf2-07dc5259a954",
"Result": "0xC0370103",
"Parameter0": "{\"RuntimeStateFilePath\":\"C:\\\\ProgramData\\\\Microsoft\\\\Windows\\\\Containers\\\\Snapshots\\\\7a502cbe-ae09-4bef-a804-acb145ffff9a\\\\SnapshotSavedState.vmrs\",\"SaveStateFilePath\":\"\"}"
}
},
"message": ""
}
Event ID 2019: [SystemId] Crash compute system, options 'Parameter0', result Result.
#Event ID 2020: [SystemId] Cancel operation id Parameter0 result Result.
#Event ID 2021: [SystemId] Get properties of operation id Parameter0 result Result.
#Event ID 2500: [SystemId] Create process, parameters 'Parameter1', result Result, process ID Parameter0.
#Event ID 2501: [SystemId] Terminate process, process ID Parameter0, result Result.
#Event ID 2502: [SystemId] Query process notification, process ID Parameter0, result Result, notification Parameter1 / Parameter2.
#Event ID 2503: [SystemId] Queue process notification Parameter1 / Parameter2, process ID Parameter0.
#Event ID 2504: The dynamic memory balancer timer was started.
#Description
The dynamic memory balancer timer was started.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 2504,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:25:20.753476+00:00",
"event_record_id": 38,
"correlation": {
"ActivityID": "46199242-6BA3-49E9-87C1-DF661282CCC7"
},
"execution": {
"process_id": 3904,
"thread_id": 7256
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {}
},
"message": ""
}
Event ID 2505: [SystemId] Start compute system preservation with settings 'Parameter0', result Result.
#Event ID 2506: [SystemId] Finalize compute system preservation with settings 'Parameter0', result Result.
#Event ID 2507: [SystemId] Start migration of compute system with settings 'Parameter0', result Result.
#Event ID 2508: [SystemId] Start migration transfer of compute system with settings 'Parameter0', result Result.
#Event ID 2509: [SystemId] Wait for compute system migration to be finalized with settings 'Parameter0', result Result.
#Event ID 2510: [SystemId] Migrate compute system with settings 'Parameter0', result Result.
#Event ID 2511: [SystemId] Finalize compute system with settings 'Parameter0', result Result.
#Event ID 10000: The Host Compute Service failed to start: ErrorMessage (ErrorCode).
#Event ID 10000: The Host Compute Service failed to start: ErrorMessage (ErrorCode)
#Description
The Host Compute Service failed to start: ().
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 10001: The dynamic memory balancer failed to start because the host system is not supported.
#Description
The dynamic memory balancer failed to start because the host system is not supported.
Message #
Event ID 10001: The dynamic memory balancer failed to start because the host system is not supported
#Description
The dynamic memory balancer failed to start because the host system is not supported.
Event ID 10002: Virtual machine 'Parameter0' cannot be started on this server.
#Event ID 10002: Virtual machine 'Parameter0' cannot be started on this server
#Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString |
Event ID 10003: Virtual machine 'Parameter0' cannot be started on this server.
#Event ID 10003: Virtual machine 'Parameter0' cannot be started on this server
#Description
Virtual machine 'Parameter0' cannot be started on this server.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString |
Event ID 10004: 'Parameter0' failed to start worker process: Parameter2 (Parameter3).
#Event ID 10004: 'Parameter0' failed to start worker process: Parameter2 (Parameter3)
#Description
'Parameter0' failed to start worker process: Parameter2 (Parameter3). (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10005: Failed to start worker process: Parameter2 (Parameter3).
#Event ID 10005: Failed to start worker process: Parameter2 (Parameter3)
#Description
Failed to start worker process: (). (Virtual machine ID ).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10006: The virtual machine 'VmName' with RAM size Parameter0 MB failed to reset due to insufficient memory.
#Event ID 10006: The virtual machine 'VmName' with RAM size Parameter0 MB failed to reset due to insufficient memory
#Fields #
| Name | Description |
|---|---|
VmName UnicodeString | |
VmId UnicodeString | |
Parameter0 UInt64 | |
Parameter1 UInt64 |
Event ID 10007: Failed to reset the virtual machine 'VmName' (Virtual machine ID VmId).
#Event ID 10007: Failed to reset the virtual machine 'VmName' (Virtual machine ID VmId)
#Description
Failed to reset the virtual machine 'VmName' (Virtual machine ID VmId).
Fields #
| Name | Description |
|---|---|
VmName UnicodeString | |
VmId UnicodeString | |
Parameter0 UInt64 | |
Parameter1 UInt64 |
Event ID 10008: The virtual machine 'Parameter0' with RAM size Parameter2 MB failed to start due to insufficient memory.
#Event ID 10008: The virtual machine 'Parameter0' with RAM size Parameter2 MB failed to start due to insufficient memory
#Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10009: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
#Event ID 10009: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1)
#Description
Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10010: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
Message #
Event ID 10010: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
Event ID 10011: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
Message #
Event ID 10011: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
Event ID 10013: DM operation add for the virtual machine 'Parameter0' took more than Parameter2 seconds (Virtual machine ID Parameter1).
#Event ID 10013: DM operation add for the virtual machine 'Parameter0' took more than Parameter2 seconds (Virtual machine ID Parameter1)
#Description
DM operation add for the virtual machine 'Parameter0' took more than Parameter2 seconds (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 10014: DM operation remove for the virtual machine 'Parameter0' took more than Parameter2 seconds (Virtual machine ID Parameter1).
#Event ID 10014: DM operation remove for the virtual machine 'Parameter0' took more than Parameter2 seconds (Virtual machine ID Parameter1)
#Description
DM operation remove for the virtual machine 'Parameter0' took more than Parameter2 seconds (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 10015: The dynamic memory balancer could not balance the system due to high memory pressure.
#Description
The dynamic memory balancer could not balance the system due to high memory pressure.
Message #
Event ID 10015: The dynamic memory balancer could not balance the system due to high memory pressure
#Description
The dynamic memory balancer could not balance the system due to high memory pressure.
Event ID 10016: Smart Paging was active for the virtual machine 'Parameter0' more than Parameter2 seconds (Virtual machine ID Parameter1).
#Event ID 10016: Smart Paging was active for the virtual machine 'Parameter0' more than Parameter2 seconds (Virtual machine ID Parameter1)
#Description
Smart Paging was active for the virtual machine 'Parameter0' more than Parameter2 seconds (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 10017: The virtual machine 'Parameter0' stopped using Smart Paging after Parameter2 seconds (Virtual machine ID Parameter1).
#Event ID 10017: The virtual machine 'Parameter0' stopped using Smart Paging after Parameter2 seconds (Virtual machine ID Parameter1)
#Description
The virtual machine 'Parameter0' stopped using Smart Paging after Parameter2 seconds (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 10018: DM operation add for the virtual machine 'Parameter0' failed with error: Parameter2 (Parameter3) (Virtual machine ID Parameter1).
#Event ID 10018: DM operation add for the virtual machine 'Parameter0' failed with error: Parameter2 (Parameter3) (Virtual machine ID Parameter1)
#Description
DM operation add for the virtual machine 'Parameter0' failed with error: Parameter2 (Parameter3) (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10019: DM operation remove for the virtual machine 'Parameter0' failed with error: Parameter2 (Parameter3) (Virtual machine ID Parameter1).
#Event ID 10019: DM operation remove for the virtual machine 'Parameter0' failed with error: Parameter2 (Parameter3) (Virtual machine ID Parameter1)
#Description
DM operation remove for the virtual machine 'Parameter0' failed with error: Parameter2 (Parameter3) (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10020: The dynamic memory balancer could not add memory to the virtual machine 'Parameter0' because its configured maximum has been reached (Virtual machine ID Parameter1).
#Event ID 10020: The dynamic memory balancer could not add memory to the virtual machine 'Parameter0' because its configured maximum has been reached (Virtual machine ID Parameter1)
#Description
The dynamic memory balancer could not add memory to the virtual machine 'Parameter0' because its configured maximum has been reached (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString |
Event ID 10021: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
#Event ID 10021: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1)
#Description
Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10022: The memory specified for the virtual machine cannot be supported by this host.
#Description
The memory specified for the virtual machine cannot be supported by this host. For instance, this can happen when the startup memory for the virtual machine exceeds the total memory on the host.
Message #
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10022: The memory specified for the virtual machine cannot be supported by this host
#Description
The memory specified for the virtual machine cannot be supported by this host. For instance, this can happen when the startup memory for the virtual machine exceeds the total memory on the host.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10023: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
Message #
Event ID 10023: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too low.
Event ID 10024: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too high.
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too high.
Message #
Event ID 10024: The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too high
#Description
The root memory reserve key (HKLM\Software\Microsoft\Windows NT\CurrentVersion\Virtualization\MemoryReserve) is set too high.
Event ID 10025: An invalid value is set for the DHMM policy.
#Description
An invalid value is set for the DHMM policy.
Message #
Event ID 10025: An invalid value is set for the DHMM policy
#Description
An invalid value is set for the DHMM policy.
Event ID 10026: An invalid value is set for the DHMM policy.
#Description
An invalid value is set for the DHMM policy.
Message #
Event ID 10026: An invalid value is set for the DHMM policy
#Description
An invalid value is set for the DHMM policy.
Event ID 10028: The virtual machine 'Parameter0' failed to start due to compute-less and resource-less NUMA node (NUMA node index Parameter2).
#Event ID 10028: The virtual machine 'Parameter0' failed to start due to compute-less and resource-less NUMA node (NUMA node index Parameter2)
#Description
The virtual machine 'Parameter0' failed to start due to compute-less and resource-less NUMA node (NUMA node index Parameter2). (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 10029: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
#Event ID 10029: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1)
#Description
Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString |
Event ID 10030: The requested virtual NUMA node count for the virtual machine cannot be supported by this host.
#Event ID 10030: The requested virtual NUMA node count for the virtual machine cannot be supported by this host
#Description
The requested virtual NUMA node count for the virtual machine cannot be supported by this host.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10031: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
#Event ID 10031: Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1)
#Description
Failed to start the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString |
Event ID 10032: Not all device specific physical NUMA nodes are assigned to the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
#Event ID 10032: Not all device specific physical NUMA nodes are assigned to the virtual machine 'Parameter0' (Virtual machine ID Parameter1)
#Description
Not all device specific physical NUMA nodes are assigned to the virtual machine 'Parameter0' (Virtual machine ID Parameter1). Try to use the server NUMA topology.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString |
Event ID 10033: NUMA node assignment is not optimal for the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
#Event ID 10033: NUMA node assignment is not optimal for the virtual machine 'Parameter0' (Virtual machine ID Parameter1)
#Description
NUMA node assignment is not optimal for the virtual machine 'Parameter0' (Virtual machine ID Parameter1).
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString |
Event ID 11000: The specified compute system configuration is invalid: ErrorMessage (ErrorCode, 'Parameter0').
#Event ID 11000: The specified compute system configuration is invalid: ErrorMessage (ErrorCode, 'Parameter0')
#Description
The specified compute system configuration is invalid: ErrorMessage (ErrorCode, 'Parameter0').
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11001: The specified property query is invalid: ErrorMessage (ErrorCode, 'Parameter0').
#Event ID 11001: The specified property query is invalid: ErrorMessage (ErrorCode, 'Parameter0')
#Description
The specified property query is invalid: ErrorMessage (ErrorCode, 'Parameter0').
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11002: The specified options document is invalid: ErrorMessage (ErrorCode, 'Parameter0').
#Event ID 11002: The specified options document is invalid: ErrorMessage (ErrorCode, 'Parameter0')
#Description
The specified options document is invalid: ErrorMessage (ErrorCode, 'Parameter0').
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11003: The specified settings document is invalid: ErrorMessage (ErrorCode, 'Parameter0').
#Event ID 11003: The specified settings document is invalid: ErrorMessage (ErrorCode, 'Parameter0')
#Description
The specified settings document is invalid: ErrorMessage (ErrorCode, 'Parameter0').
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11004: Failed to recover compute system (SystemId): ErrorMessage (ErrorCode).
#Event ID 11004: Failed to recover compute system (SystemId): ErrorMessage (ErrorCode)
#Description
Failed to recover compute system (): ().
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 11005: [SystemId] The specified settings document is invalid: A required field 'Parameter0' is not present.
#Event ID 11005: [SystemId] The specified settings document is invalid: A required field 'Parameter0' is not present
#Description
[SystemId] The specified settings document is invalid: A required field 'Parameter0' is not present.
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11006: [SystemId] The specified settings document is invalid: A field 'Parameter0' contains an invalid value.
#Event ID 11006: [SystemId] The specified settings document is invalid: A field 'Parameter0' contains an invalid value
#Description
[SystemId] The specified settings document is invalid: A field 'Parameter0' contains an invalid value.
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11007: The specified save options are invalid: ErrorMessage (ErrorCode, 'Parameter0').
#Event ID 11007: The specified save options are invalid: ErrorMessage (ErrorCode, 'Parameter0')
#Description
The specified save options are invalid: ErrorMessage (ErrorCode, 'Parameter0').
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11008: Cannot create system 'VmlEventLog.SystemId' since Hyper-V is not installed on the host.
#Description
Cannot create system 'VmlEventLog.SystemId' since Hyper-V is not installed on the host.
Message #
Fields #
| Name | Description |
|---|---|
SystemId | |
ErrorMessage | |
ErrorCode |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Hyper-V-Compute",
"guid": "17103E3F-3C6E-4677-BB17-3B267EB5BE57",
"event_source_name": "",
"event_id": 11008,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T23:41:09.198537+00:00",
"event_record_id": 3,
"correlation": {},
"execution": {
"process_id": 7344,
"thread_id": 8756
},
"channel": "Microsoft-Windows-Hyper-V-Compute-Admin",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"VmlEventLog": {
"SystemId": "23A0322C-4270-471D-AD61-428A1A5BBF7D",
"ErrorMessage": "%%2151088386",
"ErrorCode": "0x80370102"
}
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 11008: Cannot create system 'SystemId' since Hyper-V is not installed on the host
#Description
Cannot create system 'SystemId' since Hyper-V is not installed on the host.
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 11009: A resource URI 'Parameter0' specified in the compute system configuration field 'Parameter1' was not found: ErrorMessage (ErrorCode).
#Event ID 11009: A resource URI 'Parameter0' specified in the compute system configuration field 'Parameter1' was not found: ErrorMessage (ErrorCode)
#Description
A resource URI 'Parameter0' specified in the compute system configuration field 'Parameter1' was not found: ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString | |
Parameter1 UnicodeString |
Event ID 11500: The specified number of processors is not supported by the system (Parameter0).
#Event ID 11500: The specified number of processors is not supported by the system (Parameter0)
#Description
The specified number of processors is not supported by the system ().
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 Int64 |
Event ID 11501: The specified relative processor weight is out of valid range (Parameter0).
#Event ID 11501: The specified relative processor weight is out of valid range (Parameter0)
#Description
The specified relative processor weight is out of valid range ().
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 Int64 |
Event ID 11502: The specified limit for the processors usage is out of valid range (Parameter0).
#Event ID 11502: The specified limit for the processors usage is out of valid range (Parameter0)
#Description
The specified limit for the processors usage is out of valid range ().
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 Int64 |
Event ID 11503: The specified Storage Quality of Service settings are not supported on Data Volume 'Parameter0': ErrorMessage (ErrorCode) (Container ID SystemId).
#Event ID 11503: The specified Storage Quality of Service settings are not supported on Data Volume 'Parameter0': ErrorMessage (ErrorCode) (Container ID SystemId)
#Description
The specified Storage Quality of Service settings are not supported on Data Volume 'Parameter0': ErrorMessage (ErrorCode) (Container ID SystemId).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11504: Storage Quality of Service has been applied to a Container and to one or mode Data Volumes that reside on the same disk.
#Event ID 11504: Storage Quality of Service has been applied to a Container and to one or mode Data Volumes that reside on the same disk
#Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 11505: The specified memory amount is out of valid range (Parameter0).
#Event ID 11505: The specified memory amount is out of valid range (Parameter0)
#Description
The specified memory amount is out of valid range ().
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 Int64 |
Event ID 11506: The specified process parameters are invalid: ErrorMessage (ErrorCode, 'Parameter0').
#Event ID 11506: The specified process parameters are invalid: ErrorMessage (ErrorCode, 'Parameter0')
#Description
The specified process parameters are invalid: ErrorMessage (ErrorCode, 'Parameter0').
Fields #
| Name | Description |
|---|---|
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 11507: Failed to setup the external credentials for Container 'SystemId': ErrorMessage (ErrorCode).
#Event ID 11507: Failed to setup the external credentials for Container 'SystemId': ErrorMessage (ErrorCode)
#Description
Failed to setup the external credentials for Container 'SystemId': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 12000: Failed to create the Virtual Machine for Hyper-V Container 'SystemId': ErrorMessage (ErrorCode).
#Event ID 12000: Failed to create the Virtual Machine for Hyper-V Container 'SystemId': ErrorMessage (ErrorCode)
#Description
Failed to create the Virtual Machine for Hyper-V Container 'SystemId': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 12001: Cannot start Hyper-V Container 'SystemId' since the hypervisor is not running in the host.
#Event ID 12001: Cannot start Hyper-V Container 'SystemId' since the hypervisor is not running in the host
#Description
Cannot start Hyper-V Container 'SystemId' since the hypervisor is not running in the host.
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 12002: Failed to create the Virtual Machine for Hyper-V Container template 'SystemId': ErrorMessage (ErrorCode).
#Event ID 12002: Failed to create the Virtual Machine for Hyper-V Container template 'SystemId': ErrorMessage (ErrorCode)
#Description
Failed to create the Virtual Machine for Hyper-V Container template 'SystemId': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 12003: Cannot create a template for a Hyper-V Container, reached the maximum number of templates.
#Description
Cannot create a template for a Hyper-V Container, reached the maximum number of templates.
Message #
Event ID 12003: Cannot create a template for a Hyper-V Container, reached the maximum number of templates
#Description
Cannot create a template for a Hyper-V Container, reached the maximum number of templates.
Event ID 12004: Failed to setup the template for a Hyper-V Container: ErrorMessage (ErrorCode).
#Event ID 12004: Failed to setup the template for a Hyper-V Container: ErrorMessage (ErrorCode)
#Description
Failed to setup the template for a Hyper-V Container: ().
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 12005: Failed to setup Windows Defender for Container 'SystemId', Windows Defender is not available on the host.
#Event ID 12005: Failed to setup Windows Defender for Container 'SystemId', Windows Defender is not available on the host
#Description
Failed to setup Windows Defender for Container 'SystemId', Windows Defender is not available on the host.
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString |
Event ID 12006: The Hyper-V Container 'SystemId' encountered a protocol error and was terminated.
#Event ID 12006: The Hyper-V Container 'SystemId' encountered a protocol error and was terminated
#Description
The Hyper-V Container 'SystemId' encountered a protocol error and was terminated. An unexpected notification (Parameter0) was received.
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 Int64 |
Event ID 12100: Failed to create network endpoint for Container 'SystemId': ErrorMessage (ErrorCode).
#Event ID 12100: Failed to create network endpoint for Container 'SystemId': ErrorMessage (ErrorCode)
#Description
Failed to create network endpoint for Container 'SystemId': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 12101: Failed to delete network endpoint for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
#Event ID 12101: Failed to delete network endpoint for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode)
#Description
Failed to delete network endpoint for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 GUID |
Event ID 12102: Failed to attach network endpoint to Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
#Event ID 12102: Failed to attach network endpoint to Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode)
#Description
Failed to attach network endpoint to Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 GUID |
Event ID 12103: Failed to detach network endpoint from Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
#Event ID 12103: Failed to detach network endpoint from Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode)
#Description
Failed to detach network endpoint from Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 GUID |
Event ID 12104: Failed to query network endpoint properties for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
#Event ID 12104: Failed to query network endpoint properties for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode)
#Description
Failed to query network endpoint properties for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 GUID |
Event ID 12105: Failed to create network adapter for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
#Event ID 12105: Failed to create network adapter for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode)
#Description
Failed to create network adapter for Container 'SystemId', network endpoint ID 'Parameter0': ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 GUID |
Event ID 12106: Cannot perform the operation for compute system 'SystemId' as that system has one or more devices assigned to it;: ErrorMessage (ErrorCode).
#Event ID 12106: Cannot perform the operation for compute system 'SystemId' as that system has one or more devices assigned to it;: ErrorMessage (ErrorCode)
#Description
Cannot perform the operation for compute system 'SystemId' as that system has one or more devices assigned to it;: ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 12107: Cannot perform the operation for compute system 'SystemId' because it is assigned one or more GPU partitions;: ErrorMessage (ErrorCode).
#Event ID 12107: Cannot perform the operation for compute system 'SystemId' because it is assigned one or more GPU partitions;: ErrorMessage (ErrorCode)
#Description
Cannot perform the operation for compute system 'SystemId' because it is assigned one or more GPU partitions;: ErrorMessage (ErrorCode).
Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 40012: Memory weight above maximum.
#Event ID 40012: Memory weight above maximum
#Description
Memory weight above maximum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40014: Memory virtual quantity above maximum.
#Event ID 40014: Memory virtual quantity above maximum
#Description
Memory virtual quantity above maximum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40016: Memory virtual quantity below minimum.
#Event ID 40016: Memory virtual quantity below minimum
#Description
Memory virtual quantity below minimum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40018: Memory virtual quantity not properly aligned.
#Event ID 40018: Memory virtual quantity not properly aligned
#Description
Memory virtual quantity not properly aligned.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40020: Memory virtual quantity above limit.
#Event ID 40020: Memory virtual quantity above limit
#Description
Memory virtual quantity above limit.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40022: Memory virtual quantity below reservation.
#Event ID 40022: Memory virtual quantity below reservation
#Description
Memory virtual quantity below reservation.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40024: Memory limit above maximum.
#Event ID 40024: Memory limit above maximum
#Description
Memory limit above maximum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40026: Memory limit below minimum.
#Event ID 40026: Memory limit below minimum
#Description
Memory limit below minimum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40028: Memory limit not properly aligned.
#Event ID 40028: Memory limit not properly aligned
#Description
Memory limit not properly aligned.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40030: Memory reservation above maximum.
#Event ID 40030: Memory reservation above maximum
#Description
Memory reservation above maximum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40032: Memory reservation below minimum.
#Event ID 40032: Memory reservation below minimum
#Description
Memory reservation below minimum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40034: Memory reservation not properly aligned.
#Event ID 40034: Memory reservation not properly aligned
#Description
Memory reservation not properly aligned.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40036: Memory target memory buffer above maximum.
#Event ID 40036: Memory target memory buffer above maximum
#Description
Memory target memory buffer above maximum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40038: Memory target memory buffer below minimum.
#Event ID 40038: Memory target memory buffer below minimum
#Description
Memory target memory buffer below minimum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40048: Invalid memory alignment.
#Event ID 40048: Invalid memory alignment
#Description
Invalid memory alignment.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40050: The version of the virtual machine is not compatible with the alignment.
#Event ID 40050: The version of the virtual machine is not compatible with the alignment
#Description
The version of the virtual machine is not compatible with the alignment.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40052: Memory weight is below minimum.
#Event ID 40052: Memory weight is below minimum
#Description
Memory weight is below minimum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40054: The version or generation of the virtual machine is not compatible with SGX.
#Event ID 40054: The version or generation of the virtual machine is not compatible with SGX
#Description
The version or generation of the virtual machine is not compatible with SGX.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40056: SGX launch control mode is invalid.
#Event ID 40056: SGX launch control mode is invalid
#Description
SGX launch control mode is invalid.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40058: Default SGX launch control MSR string is invalid.
#Event ID 40058: Default SGX launch control MSR string is invalid
#Description
Default SGX launch control MSR string is invalid.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40060: Memory per virtual NUMA node is above maximum.
#Event ID 40060: Memory per virtual NUMA node is above maximum
#Description
Memory per virtual NUMA node is above maximum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40062: Memory per virtual NUMA node is below minimum.
#Event ID 40062: Memory per virtual NUMA node is below minimum
#Description
Memory per virtual NUMA node is below minimum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40064: Memory per virtual NUMA node is not properly aligned.
#Event ID 40064: Memory per virtual NUMA node is not properly aligned
#Description
Memory per virtual NUMA node is not properly aligned.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40066: SGX memory is above maximum.
#Event ID 40066: SGX memory is above maximum
#Description
SGX memory is above maximum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40068: SGX memory is below minimum.
#Event ID 40068: SGX memory is below minimum
#Description
SGX memory is below minimum.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40070: SGX memory is not porperly aligned.
#Event ID 40070: SGX memory is not porperly aligned
#Description
SGX memory is not porperly aligned.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 40072: Pool id specified is unknown.
#Event ID 40072: Pool id specified is unknown
#Description
Pool id specified is unknown.
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 65526: SystemId|ErrorMessage|ErrorCode.
#Event ID 65527: %.
#Event ID 65528: SystemId|ErrorMessage|ErrorCode.
#Event ID 65529: task_065529
#Event ID 65530: --
#Event ID 65532: SystemId|ErrorMessage|ErrorCode.
#Event ID 65532: SystemId|ErrorMessage|
#Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString |
Event ID 65533: SystemId|ErrorMessage|ErrorCode|Parameter0.
#Event ID 65533: SystemId|ErrorMessage|ErrorCode|
#Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 UnicodeString |
Event ID 65534: SystemId|ErrorMessage|ErrorCode|Parameter0.
#Event ID 65534: SystemId|ErrorMessage|ErrorCode|
#Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 Int64 |
Event ID 65535: SystemId|ErrorMessage|ErrorCode|Parameter0.
#Event ID 65535: SystemId|ErrorMessage|ErrorCode|
#Fields #
| Name | Description |
|---|---|
SystemId UnicodeString | |
ErrorMessage UnicodeString | |
ErrorCode UnicodeString | |
Parameter0 GUID |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 17103e3f-3c6e-4677-bb17-3b267eb5be57
Defined in vmcomputeeventlog.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02