Microsoft-Windows-Hyper-V-Guest-Drivers-Storage-Filter
8 events across 2 channels
Event ID 1: The Virtual Storage Filter Driver failed to initialize (NTStatus).
#Description
The Virtual Storage Filter Driver failed to initialize (NTStatus).
Message #
Fields #
| Name | Description |
|---|---|
NTStatus HexInt32 | NTSTATUS reference |
Event ID 2: The Virtual Storage Filter Driver failed to intialize disk (NTStatus).
#Description
The Virtual Storage Filter Driver failed to intialize disk (NTStatus).
Message #
Fields #
| Name | Description |
|---|---|
NTStatus HexInt32 | NTSTATUS reference |
Event ID 3: The Virtual Storage Filter Driver is active for disk at location Location (NTStatus).
#Description
The Virtual Storage Filter Driver is active for disk at location Location (NTStatus).
Message #
Fields #
| Name | Description |
|---|---|
Location UnicodeString | |
NTStatus HexInt32 | NTSTATUS reference |
Event ID 4: The Virtual Storage Filter Driver is inactive for disk at location Location (NTStatus).
#Description
The Virtual Storage Filter Driver is inactive for disk at location Location (NTStatus).
Message #
Fields #
| Name | Description |
|---|---|
Location UnicodeString | |
NTStatus HexInt32 | NTSTATUS reference |
Event ID 5: The Virtual Storage Filter Driver is disabled through the registry.
#Description
The Virtual Storage Filter Driver is disabled through the registry. It is inactive for all disk drives.
Message #
Event ID 202: Dispatching a read request.
#Event ID 203: Dispatching a write request.
#Event ID 208: Completing an IO (read/write) request.
#Description
Completing an IO (read/write) request.
Message #
Fields #
| Name | Description |
|---|---|
Irp Pointer | |
NTStatus HexInt32 | NTSTATUS reference |
SrbStatus UInt8 | |
ScsiStatus UInt8 | |
SenseKey UInt8 | |
AddSense UInt8 | |
AddSenseQ UInt8 | |
OriginalIrp Pointer |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 0b9fdccc-451c-449c-9bd8-6756fcc6091a
Defined in vmstorfl.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02