Microsoft-Windows-Hyper-V-CrashDump

14 events across 3 channels

Event ID 1500: [Virtual machine VmId]

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Operational

Description

[Virtual machine ].

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1500: [Virtual machine VmId] TraceData.

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Microsoft-Windows-Hyper-V-Worker-Analytic

Description

[Virtual machine VmId] TraceData.

Message #

[Virtual machine %3] %1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1510: [Virtual machine VmId]

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Operational

Description

[Virtual machine ].

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1510: [Virtual machine VmId] TraceData.

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Microsoft-Windows-Hyper-V-Worker-Analytic

Description

[Virtual machine VmId] TraceData.

Message #

[Virtual machine %3] %1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1520: [Virtual machine VmId]

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Operational

Description

[Virtual machine ].

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1520: [Virtual machine VmId] TraceData.

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Microsoft-Windows-Hyper-V-Worker-Analytic

Description

[Virtual machine VmId] TraceData.

Message #

[Virtual machine %3] %1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1530: [Virtual machine VmId]

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Operational

Description

[Virtual machine ].

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 1530: [Virtual machine VmId] TraceData.

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Microsoft-Windows-Hyper-V-Worker-Analytic

Description

[Virtual machine VmId] TraceData.

Message #

[Virtual machine %3] %1

Fields #

NameDescription
TraceData UnicodeString
VmName UnicodeString
VmId UnicodeString
StackFrameCount UInt32
StackFrame Pointer
ModuleCount UInt32
Module Int32

Event ID 40000: [Virtual machine VmId] 'VmName' device Device - A fatal error occured while processing a protocol message from the guest

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Operational

Description

[Virtual machine VmId] 'VmName' device Device - A fatal error occured while processing a protocol message from the guest.

Fields #

NameDescription
VmName UnicodeString
VmId UnicodeString
Device UnicodeString

Event ID 40000: [Virtual machine VmId] 'VmName' device Device - A fatal error occured while processing a protocol message from the guest.

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Microsoft-Windows-Hyper-V-Worker-Admin

Description

[Virtual machine VmId] 'VmName' device Device - A fatal error occured while processing a protocol message from the guest.

Message #

[Virtual machine %2] '%1' device %3 - A fatal error occured while processing a protocol message from the guest.

Fields #

NameDescription
VmName UnicodeString
VmId UnicodeString
Device UnicodeString

Event ID 40001: [Virtual machine VmId] 'VmName' A guest crash dump was successfully written to

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Operational

Description

[Virtual machine VmId] 'VmName' A guest crash dump was successfully written to DumpFile.

Fields #

NameDescription
VmName UnicodeString
VmId UnicodeString
DumpFile UnicodeString

Event ID 40001: [Virtual machine VmId] 'VmName' A guest crash dump was successfully written to DumpFile.

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Microsoft-Windows-Hyper-V-Worker-Admin

Description

[Virtual machine VmId] 'VmName' A guest crash dump was successfully written to DumpFile.

Message #

[Virtual machine %2] '%1' A guest crash dump was successfully written to %3.

Fields #

NameDescription
VmName UnicodeString
VmId UnicodeString
DumpFile UnicodeString

Event ID 40002: [Virtual machine VmId] 'VmName' A guest crash dump was started but did not complete successfully

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Operational

Description

[Virtual machine VmId] 'VmName' A guest crash dump was started but did not complete successfully.

Fields #

NameDescription
VmName UnicodeString
VmId UnicodeString

Event ID 40002: [Virtual machine VmId] 'VmName' A guest crash dump was started but did not complete successfully.

#
Provider
Microsoft-Windows-Hyper-V-CrashDump
Channel
Microsoft-Windows-Hyper-V-Worker-Admin

Description

[Virtual machine VmId] 'VmName' A guest crash dump was started but did not complete successfully.

Message #

[Virtual machine %2] '%1' A guest crash dump was started but did not complete successfully.

Fields #

NameDescription
VmName UnicodeString
VmId UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID c7c9e4f7-c41d-5c68-f104-d72a920016c7

Defined in VmCrashDump.dll, which carries the event manifest.

Observed on:

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads