Microsoft-Windows-Hyper-V-CrashDump
14 events across 3 channels
Event ID 1500: [Virtual machine VmId]
#Description
[Virtual machine ].
Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 1500: [Virtual machine VmId] TraceData.
#Event ID 1510: [Virtual machine VmId]
#Description
[Virtual machine ].
Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 1510: [Virtual machine VmId] TraceData.
#Event ID 1520: [Virtual machine VmId]
#Description
[Virtual machine ].
Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 1520: [Virtual machine VmId] TraceData.
#Event ID 1530: [Virtual machine VmId]
#Description
[Virtual machine ].
Fields #
| Name | Description |
|---|---|
TraceData UnicodeString | |
VmName UnicodeString | |
VmId UnicodeString | |
StackFrameCount UInt32 | |
StackFrame Pointer | |
ModuleCount UInt32 | |
Module Int32 |
Event ID 1530: [Virtual machine VmId] TraceData.
#Event ID 40000: [Virtual machine VmId] 'VmName' device Device - A fatal error occured while processing a protocol message from the guest
#Description
[Virtual machine VmId] 'VmName' device Device - A fatal error occured while processing a protocol message from the guest.
Fields #
| Name | Description |
|---|---|
VmName UnicodeString | |
VmId UnicodeString | |
Device UnicodeString |
Event ID 40000: [Virtual machine VmId] 'VmName' device Device - A fatal error occured while processing a protocol message from the guest.
#Event ID 40001: [Virtual machine VmId] 'VmName' A guest crash dump was successfully written to
#Description
[Virtual machine VmId] 'VmName' A guest crash dump was successfully written to DumpFile.
Fields #
| Name | Description |
|---|---|
VmName UnicodeString | |
VmId UnicodeString | |
DumpFile UnicodeString |
Event ID 40001: [Virtual machine VmId] 'VmName' A guest crash dump was successfully written to DumpFile.
#Event ID 40002: [Virtual machine VmId] 'VmName' A guest crash dump was started but did not complete successfully
#Description
[Virtual machine VmId] 'VmName' A guest crash dump was started but did not complete successfully.
Fields #
| Name | Description |
|---|---|
VmName UnicodeString | |
VmId UnicodeString |
Event ID 40002: [Virtual machine VmId] 'VmName' A guest crash dump was started but did not complete successfully.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID c7c9e4f7-c41d-5c68-f104-d72a920016c7
Defined in VmCrashDump.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02