Microsoft-Windows-Hyper-V-Guest-Drivers-Storage-Filter

Event ID 1: The Virtual Storage Filter Driver failed to initialize (NTStatus).

#
Channel
Admin

Message #

The Virtual Storage Filter Driver failed to initialize (%1).

Fields #

NameDescription
NTStatus HexInt32NTSTATUS reference

Event ID 2: The Virtual Storage Filter Driver failed to intialize disk (NTStatus).

#
Channel
Admin

Message #

The Virtual Storage Filter Driver failed to intialize disk (%1).

Fields #

NameDescription
NTStatus HexInt32NTSTATUS reference

Event ID 3: The Virtual Storage Filter Driver is active for disk at location Location (NTStatus).

#
Channel
Admin

Message #

The Virtual Storage Filter Driver is active for disk at location %1 (%2).

Fields #

NameDescription
Location UnicodeString
NTStatus HexInt32NTSTATUS reference

Event ID 4: The Virtual Storage Filter Driver is inactive for disk at location Location (NTStatus).

#
Channel
Admin

Message #

The Virtual Storage Filter Driver is inactive for disk at location %1 (%2).

Fields #

NameDescription
Location UnicodeString
NTStatus HexInt32NTSTATUS reference

Event ID 5: The Virtual Storage Filter Driver is disabled through the registry.

#
Channel
Admin

Description

The Virtual Storage Filter Driver is disabled through the registry. It is inactive for all disk drives.

Message #

The Virtual Storage Filter Driver is disabled through the registry. It is inactive for all disk drives.

Event ID 202: Dispatching a read request.

#
Channel
Debug
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinblocks UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 203: Dispatching a write request.

#
Channel
Debug
Task
Port
Opcode
Dispatchingofrequest.

Fields #

NameDescription
Irp Pointer
Command UInt8
LengthOfTransferinblocks UInt64
LBA HexInt64
OriginalIrp Pointer

Event ID 208: Completing an IO (read/write) request.

#
Channel
Debug
Task
Port
Opcode
Completionofrequest.

Fields #

NameDescription
Irp Pointer
NTStatus HexInt32NTSTATUS reference
SrbStatus UInt8
ScsiStatus UInt8
SenseKey UInt8
AddSense UInt8
AddSenseQ UInt8
OriginalIrp Pointer

Provenance

ETW provider GUID 0b9fdccc-451c-449c-9bd8-6756fcc6091a

Defined in vmstorfl.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB